Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2024-56180: Linux package could let attackers gain higher access

CVE-2024-56180 · published 1 day ago
Summary

Ubuntu 22.04 includes a Linux component that may allow a malicious user to elevate their privileges on the system. The problem has been corrected in newer package versions, so install the latest updates from your Linux distribution as soon as possible.

What to do
  • Update apache org.apache.eventmesh:eventmesh-meta-raft to version 1.11.0.
  • Update canonical rootio-linux to version 5.15.0-186.196.aikido.107.
  • Update canonical rootio-linux to version 5.15.0-186.196.aikido.108.
  • Update linux to version 5.15.0-198.208.aikido.116.
  • Update rootio-linux to version 5.15.0-198.208.aikido.116.
  • Update apache eventmesh to version 1.11.0 or later.
Affected software
Ecosystem VendorProductAffected versions
maven apache org.apache.eventmesh:eventmesh-meta-raft >= 1.10.1, < 1.11.0
Fix: upgrade to 1.11.0
– apache eventmesh >= 1.10.1, < 1.11.0
cpe:2.3:a:apache:eventmesh:*:*:*:*:*:*:*:*
Root:Ubuntu:22.04 canonical rootio-linux < 5.15.0-186.196.aikido.107
< 5.15.0-186.196.aikido.108
Fix: upgrade to 5.15.0-186.196.aikido.107
Root:Ubuntu:22.04 – linux < 5.15.0-198.208.aikido.116
Fix: upgrade to 5.15.0-198.208.aikido.116
Root:Ubuntu:22.04 – rootio-linux < 5.15.0-198.208.aikido.116
Fix: upgrade to 5.15.0-198.208.aikido.116
Original advisory text
CVE-2024-56180 in linux - Patched by Root
Root has patched CVE-2024-56180 in the linux package for Root:Ubuntu:22.04. Multiple fixed versions available.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published9 Oct 2026
Updated9 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta