Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2024-56180: Linux package could let attackers gain higher access
CVE-2024-56180 · published 1 day ago
Summary
Ubuntu 22.04 includes a Linux component that may allow a malicious user to elevate their privileges on the system. The problem has been corrected in newer package versions, so install the latest updates from your Linux distribution as soon as possible.
What to do
- Update apache org.apache.eventmesh:eventmesh-meta-raft to version 1.11.0.
- Update canonical rootio-linux to version 5.15.0-186.196.aikido.107.
- Update canonical rootio-linux to version 5.15.0-186.196.aikido.108.
- Update linux to version 5.15.0-198.208.aikido.116.
- Update rootio-linux to version 5.15.0-198.208.aikido.116.
- Update apache eventmesh to version 1.11.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| maven | apache | org.apache.eventmesh:eventmesh-meta-raft |
>= 1.10.1, < 1.11.0 Fix: upgrade to 1.11.0
|
| – | apache | eventmesh |
>= 1.10.1, < 1.11.0 cpe:2.3:a:apache:eventmesh:*:*:*:*:*:*:*:* |
| Root:Ubuntu:22.04 | canonical | rootio-linux |
< 5.15.0-186.196.aikido.107 < 5.15.0-186.196.aikido.108 Fix: upgrade to 5.15.0-186.196.aikido.107
|
| Root:Ubuntu:22.04 | – | linux |
< 5.15.0-198.208.aikido.116 Fix: upgrade to 5.15.0-198.208.aikido.116
|
| Root:Ubuntu:22.04 | – | rootio-linux |
< 5.15.0-198.208.aikido.116 Fix: upgrade to 5.15.0-198.208.aikido.116
|
Original advisory text
CVE-2024-56180 in linux - Patched by Root
Root has patched CVE-2024-56180 in the linux package for Root:Ubuntu:22.04. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-56180
- https://lists.apache.org/thread/k9fw0t5r7t1vbx53gs8d1r8c54rhx0wd Issue Tracking Mailing List Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/02/14/7 Mailing List Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-56180
- https://github.com/advisories/GHSA-ffvr-gmp3-xx43
- https://repo.maven.apache.org/maven2 URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56180... Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published9 Oct 2026
Updated9 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta