Illegal use of rhashtable_lookup
CVE-2024-46782

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
18 September 2024

What is CVE-2024-46782?

A vulnerability within the Linux kernel allows for a use-after-free condition in the ila_nf_input function. This oversight occurs because the ila_xlat_exit_net function incorrectly frees a resource before unregistering net hooks, which can potentially lead to unauthorized access to freed memory. The flaw is primarily located in the handling of the resource hash table, causing erratic behavior when certain network operations are conducted. Remediation requires the reversal of these function calls to ensure a synchronized control process during net hook unregistration.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 43d34110882b97ba1ec66cc8234b18983efb9abf

Linux 7f00feaf107645d95a6d87e99b4d141ac0a08efd

Linux 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 93ee345ba349922834e6a9d1dadabaedcc12dce6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.