Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-0584
HistoryJan 16, 2024 - 12:00 a.m.

CVE-2024-0584

2024-01-1600:00:00
ubuntu.com
ubuntu.com
16
linux kernel
igmp_start_timer
net component
use-after-free
information leak
igmp querypacket
local privilege escalation

AI Score

3.4

Confidence

High

EPSS

0.001

Percentile

26.3%

A use-after-free issue was found in igmp_start_timer in net/ipv4/igmp.c in
the network sub-component in the Linux Kernel. This flaw allows a local
user to observe a refcnt use-after-free issue when receiving an igmp query
packet, leading to a kernel information leak.

Bugs

Notes

Author Note
Priority reason: By using unprivileged user namespaces, this can be exploited to achieve local privilege escalation.
cache-use-only duplicates CVE-2023-6932