Logo
vulnerabilityCVE-2024-5290
Name
CVE-2024-5290
Source
NVD ( link)Debian ( link)
Description
An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa_supplicant process; other escalation paths might exist.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
wpa-supplicant
False Positive

Vulnerability Ratings#


8.8
CVSSv31
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.11
Not Affected
buildroot
master
2.11
Not Affected
yocto
kirkstone
2.10
Not Affected
yocto
master
2.11
False Positive