ZDI-CAN-24184: ZDI-24-1454: Linux Kernel nftables Improper Validation of Array Index Local Privilege Escalation Vulnerability
Published Nov 5, 2024
·Updated
This vulnerability allows local attackers to escalate privileges on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.
Affected Software
1 affected component
Linux Kernel
Event History
Nov 5, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-24184?
The severity of ZDI-CAN-24184 is rated at 8.8 on the CVSS scale.
2
How does ZDI-CAN-24184 affect the Linux Kernel?
ZDI-CAN-24184 allows local attackers to escalate privileges on affected installations of the Linux Kernel.
3
What must an attacker do to exploit ZDI-CAN-24184?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-CAN-24184.
4
When was ZDI-CAN-24184 published?
ZDI-CAN-24184 was published on November 5, 2024.
5
How can I protect my system from ZDI-CAN-24184?
To protect your system from ZDI-CAN-24184, you should apply the latest security patches provided for the Linux Kernel.