ZDI-CAN-24348: ZDI-24-1642: Linux Kernel nftables Type Confusion Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.8. The following CVEs are assigned: CVE-2024-42070.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24348?
The severity of ZDI-CAN-24348 is classified as critical due to its potential to expose sensitive information.
How do I fix ZDI-CAN-24348?
To fix ZDI-CAN-24348, upgrade to the latest patched version of the Linux Kernel.
Who is affected by ZDI-CAN-24348?
ZDI-CAN-24348 affects installations of the Linux Kernel on systems where low-privileged code execution is possible.
What type of attacks does ZDI-CAN-24348 enable?
ZDI-CAN-24348 allows local attackers to disclose sensitive information on affected systems.
What are the prerequisites for exploiting ZDI-CAN-24348?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-CAN-24348.