CVE-2024-27397 is a use-after-free flaw in the Linux kernel's netfilter/nf_tables subsystem. During control-plane transactions, a set element with a timeout could expire before the transaction completed because affected set backends did not use a transaction-start timestamp. A local low-privileged attacker could potentially crash an affected host or elevate privileges; the vulnerability affects code introduced in Linux kernel 4.1.
The issue is fixed in Linux kernel 6.7.5, 6.8, and later stable releases. Red Hat issued corrected kernel and kernel-rt packages for multiple RHEL 8 and 9 streams and rates the flaw Moderate, while CVSS assessments range from 7.0 to 7.8 depending on assumed attack complexity. Organizations should deploy current vendor kernel updates rather than cherry-picking patches; non-containerized RHEL 8 systems may temporarily disable user namespaces, but this mitigation must not be used on OpenShift because its containers require user namespaces.

Get the actors, campaigns, and ATT&CK mapping behind it.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:4352, fixing CVE-2024-27397 in the Red Hat Enterprise Linux 8 kernel-rt package.
Red Hat released RHSA-2024:4211, providing a fix for CVE-2024-27397 in the Red Hat Enterprise Linux 8 kernel.
Red Hat released RHSA-2024:4108, fixing CVE-2024-27397 in the Red Hat Enterprise Linux 9.2 Extended Update Support kernel.
Red Hat released RHSA-2024:5257 and RHSA-2024:5256 to fix CVE-2024-27397 in RHEL 9.0 SAP Update Services kernel and kernel-rt packages, respectively.
Red Hat released RHSA-2024:4740, fixing CVE-2024-27397 in the Red Hat Enterprise Linux 8.8 Extended Update Support kernel.
Red Hat released RHSA-2024:4583, providing a CVE-2024-27397 fix for the Red Hat Enterprise Linux 9 kernel.
Red Hat released RHSA-2024:4447 to fix CVE-2024-27397 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and SAP Update Services kernels.
The Linux kernel CVE team documented fixes for the nf_tables transaction-timeout flaw in kernel 6.7.5 and 6.8. The fix records a transaction-start timestamp for relevant set backend operations.
The nf_tables set-element timeout issue underlying CVE-2024-27397 was introduced in Linux kernel 4.1 by commit c3e1b005ed1c.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.