CVE-2024-6284

EUVD-2024-2405
In  https://github.com/google/nftables  IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses).

This issue affects:  https://pkg.go.dev/github.com/google/nftables@v0.1.0 

The bug was fixed in the next released version:  https://pkg.go.dev/github.com/google/nftables@v0.2.0
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
Affected Products (NVD)
VendorProductVersion
googlenftables
0.1.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
netfilternftables
0.1.0 ≤
𝑥
< 0.2.0
ADP
Debian logo
Debian Releases
Debian Product
Codename
golang-github-google-nftables
bookworm
0.1.0-4~deb12u1
fixed
forky
0.2.0-3
fixed
sid
0.2.0-3
fixed
trixie
0.2.0-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-github-google-nftables
focal
dne
jammy
dne
mantic
ignored
noble
needed
oracular
ignored
plucky
not-affected
questing
not-affected