Database/Kernel, userspace & hypervisor
Linux kernel (netfilter): nft_chain_filter NETDEV_UNREGISTER mishandling for inet/ingress basechains - UAF
CVSS 6.5CVE-2024-26808Kernel, userspace & hypervisorcurated
Impact
nft_chain_filter NETDEV_UNREGISTER mishandling for inet/ingress basechains - UAF
Who can reach it
Any tenant process in a container with CAP_NET_ADMIN
What to do
Livepatchable; otherwise drain + reboot
References
Related entries
- Linux kernel (netfilter): Use-after-free write in the netfilter subsystem - privilege escalation to rootCVE-2022-32250 · Linux kernel (netfilter)High
- Linux kernel (netfilter): Integer overflow in nft_payload_copy_vlan - stack leak plus local privilege escalationCVE-2023-0179 · Linux kernel (netfilter)High
- Linux kernel (drivers/iommu/intel): The whole node hangs. VT-d keeps re-issuing an ATS device-TLB invalidation to aCVE-2024-26891 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/iommufd): The cache-invalidation ioctl calls a driver operation that may not exist, jumpingCVE-2024-46824 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (net/xfrm): An SA created with an AF_UNSPEC selector escaped prefix-length validation, and the kernel thenCVE-2024-50142 · Linux kernel (net/xfrm)Medium
- Linux kernel (drivers/iommu/intel): Attaching a nested parent domain skips allocating the invalidation batch structureCVE-2024-56668 · Linux kernel (drivers/iommu/intel)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.