CVE-2024-0193
HIGHDescription
A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unprivileged user with CAP_NET_ADMIN capability to escalate their privileges on the system.
Is your site exposed to CVE-2024-0193?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| redhat | codeready_linux_builder_for_ibm_z_systems_eus |
| redhat | codeready_linux_builder_for_power_little_endian_eus |
| redhat | codeready_linux_builder_for_x86_64_eus |
| redhat | enterprise_linux_for_arm_64_eus |
| redhat | enterprise_linux_for_arm64 |
| redhat | enterprise_linux_for_arm64_els |
| redhat | enterprise_linux_for_ibm_z_systems |
| redhat | enterprise_linux_for_ibm_z_systems_els |
| redhat | enterprise_linux_for_ibm_z_systems_eus |
| redhat | enterprise_linux_for_power_little_endian_els |
| redhat | enterprise_linux_for_power_little_endian_eus |
| redhat | enterprise_linux_for_x86_64_els |
| redhat | enterprise_linux_for_x86_64_eus |
| redhat | enterprise_linux_for_x86_64_update_services_for_sap_solutions |
| redhat | enterprise_linux_server_aus |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions |
| redhat | codeready_linux_builder_for_arm64 |
| redhat | codeready_linux_builder_for_arm64_eus |
| redhat | codeready_linux_builder_for_arm64_eus |
| redhat | codeready_linux_builder_for_ibm_z_systems |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus |
| redhat | codeready_linux_builder_for_power_little_endian |
| redhat | codeready_linux_builder_for_power_little_endian_eus |
| redhat | codeready_linux_builder_for_power_little_endian_eus |
| redhat | codeready_linux_builder_for_x86_64_eus |
| redhat | codeready_linux_builder_for_x86_64_eus |
| redhat | enterprise_linux_for_arm_64 |
| redhat | enterprise_linux_for_arm_64 |
| redhat | enterprise_linux_for_arm_64 |
| redhat | enterprise_linux_for_arm_64_els |
| redhat | enterprise_linux_for_arm_64_els |
| redhat | enterprise_linux_for_arm_64_eus |
| redhat | enterprise_linux_for_arm_64_eus |
| redhat | enterprise_linux_for_ibm_z_systems |
| redhat | enterprise_linux_for_ibm_z_systems |
| redhat | enterprise_linux_for_ibm_z_systems |
| redhat | enterprise_linux_for_ibm_z_systems_els |
| redhat | enterprise_linux_for_ibm_z_systems_els |
| redhat | enterprise_linux_for_ibm_z_systems_eus |
| redhat | enterprise_linux_for_ibm_z_systems_eus |
| redhat | enterprise_linux_for_power_little_endian_els |
| redhat | enterprise_linux_for_power_little_endian_els |
| redhat | enterprise_linux_for_power_little_endian_eus |
| redhat | enterprise_linux_for_power_little_endian_eus |
| redhat | enterprise_linux_for_power_little_endian_eus |
| redhat | enterprise_linux_for_x86_64 |
| redhat | enterprise_linux_for_x86_64_els |
| redhat | enterprise_linux_for_x86_64_els |
| redhat | enterprise_linux_for_x86_64_eus |
| redhat | enterprise_linux_for_x86_64_eus |
| redhat | enterprise_linux_for_x86_64_update_services_for_sap_solutions |
| redhat | enterprise_linux_for_x86_64_update_services_for_sap_solutions |
| redhat | enterprise_linux_server_aus |
| redhat | enterprise_linux_server_aus |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions |
| redhat | logging_subsystem_for_red_hat_openshift |
| redhat | logging_subsystem_for_red_hat_openshift_for_arm_64 |
| redhat | logging_subsystem_for_red_hat_openshift_for_ibm_power_little_endian |
| redhat | logging_subsystem_for_red_hat_openshift_for_ibm_z_and_linuxone |
| redhat | enterprise_linux_for_x86_64_update_services_for_sap_solutions |
| redhat | enterprise_linux_for_arm_64 |
| redhat | enterprise_linux_for_ibm_z_systems |
| redhat | enterprise_linux_for_x86_64_update_services_for_sap_solutions |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-0193? +
How severe is CVE-2024-0193? +
What products are affected by CVE-2024-0193? +
How do I check if I'm vulnerable to CVE-2024-0193? +
Related Vulnerabilities
Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a soundness bug in the …
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the …
rust-openssl is a set of OpenSSL bindings for the Rust programming language. In affected versions `ssl::select_next_proto` can return a slice …
XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder …
c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when process_answer() may re-enqueue …
There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an …