Refine your search

1 vulnerability found for ESET Endpoint Antivirus for Linux by ESET, spol. s.r.o.

CVE-2026-6424 (GCVE-0-2026-6424)
Vulnerability from cvelistv5
Published
2026-07-16 08:28
Modified
2026-07-16 12:17
CWE
Summary
Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system
Impacted products
Vendor Product Version
ESET, spol. s.r.o. ESET Endpoint Antivirus for Linux Version: 13.1   <
Version: 13.0   <
Version: 12.2   <
Version: 12.1   <
Version: 12.0   <
Create a notification for this product.
   ESET, spol. s.r.o. ESET Server Security for Linux Version: 13.1   <
Version: 13.0   <
Version: 12.2   <
Version: 12.1   <
Version: 12.0   <
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-6424",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-16T12:17:24.495540Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-16T12:17:48.734Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "platforms": [
            "Linux"
          ],
          "product": "ESET Endpoint Antivirus for Linux",
          "vendor": "ESET, spol. s.r.o.",
          "versions": [
            {
              "changes": [
                {
                  "at": "13.1.5.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "13.1.3.0",
              "status": "affected",
              "version": "13.1",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "13.0.5.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "13.0.3.0",
              "status": "affected",
              "version": "13.0",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "12.2.9.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "12.2.8.0",
              "status": "affected",
              "version": "12.2",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "12.1.2.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "12.1.1.0",
              "status": "affected",
              "version": "12.1",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "12.0.14.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "12.0.13.0",
              "status": "affected",
              "version": "12.0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "13.2.3.0"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "platforms": [
            "Linux"
          ],
          "product": "ESET Server Security for Linux",
          "vendor": "ESET, spol. s.r.o.",
          "versions": [
            {
              "changes": [
                {
                  "at": "13.1.118.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "13.1.116.0",
              "status": "affected",
              "version": "13.1",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "13.0.36.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "13.0.34.0",
              "status": "affected",
              "version": "13.0",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "12.2.73.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "12.2.72.0",
              "status": "affected",
              "version": "12.2",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "12.1.407.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "12.1.406.0",
              "status": "affected",
              "version": "12.1",
              "versionType": "custom"
            },
            {
              "changes": [
                {
                  "at": "12.0.292.0",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "12.0.287.0",
              "status": "affected",
              "version": "12.0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "13.2.53.0"
            }
          ]
        }
      ],
      "datePublic": "2026-07-16T08:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Use-after-free vulnerability in ESET Linux products\u0026nbsp;potentially allowed an attacker to trigger kernel panic on the system"
            }
          ],
          "value": "Use-after-free vulnerability in ESET Linux products\u00a0potentially allowed an attacker to trigger kernel panic on the system"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-129",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-129 Pointer Manipulation"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-416",
              "description": "CWE-416 Use after free",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-16T08:28:43.649Z",
        "orgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
        "shortName": "ESET"
      },
      "references": [
        {
          "url": "https://support.eset.com/en/ca8972-eset-customer-advisory-use-after-free-vulnerability-in-eset-security-products-for-linux-fixed"
        }
      ],
      "source": {
        "advisory": "CA8972",
        "discovery": "UNKNOWN"
      },
      "title": "Use-after-free vulnerability in ESET security products for Linux",
      "x_generator": {
        "engine": "Vulnogram 1.0.2"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "4a9b9929-2450-4021-b7b9-469a0255b215",
    "assignerShortName": "ESET",
    "cveId": "CVE-2026-6424",
    "datePublished": "2026-07-16T08:28:43.649Z",
    "dateReserved": "2026-04-16T08:13:25.859Z",
    "dateUpdated": "2026-07-16T12:17:48.734Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}