High severity8.8NVD Advisory· Published Aug 7, 2024· Updated Jun 17, 2026
CVE-2024-5290
CVE-2024-5290
Description
An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root).
Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa_supplicant process; other escalation paths might exist.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:w1.fi:wpa_supplicant:-:*:*:*:*:*:*:*
- Canonical Ltd./wpa_supplicantv5Range: 2:2.10-15
Patches
Vulnerability mechanics
References
3- bugs.launchpad.net/ubuntu/+source/wpa/+bug/2067613nvdExploitIssue Tracking
- snyk.io/blog/abusing-ubuntu-root-privilege-escalation/nvdExploitThird Party Advisory
- ubuntu.com/security/notices/USN-6945-1nvdVendor Advisory
News mentions
0No linked articles in our index yet.