---
title: "CVE-2024-6284\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2024-6284?format=md
keywords: index, follow
---

# CVE-2024-6284

Publication date 3 July 2024

Last updated 24 June 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

In https://github.com/google/nftables  IP addresses were encoded in the
wrong byte order, resulting in an nftables configuration which does not
work as intended (might block or not block the desired addresses).
This issue affects:  https://pkg.go.dev/github.com/google/nftables@v0.1.0
The bug was fixed in the next released version:
https://pkg.go.dev/github.com/google/nftables@v0.2.0

[Read the notes from the security team](https://ubuntu.com/security/CVE-2024-6284?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| golang-github-google-nftables | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Ignored end of life, was needed |
| 24.04 LTS noble | Vulnerable |
| 23.10 mantic | Ignored end of life, was needs-triage |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [alexmurray](https://launchpad.net/~alexmurray)

crowsec-firewall-bouncer needs a no-change rebuild once
golang-github-google-nftables is patched to ensure it is also patched
since it is Built-Using

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6284)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2024-6284)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2024-6284)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2024-6284)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2024-6284>
* <https://github.com/google/nftables/issues/225>
* <https://github.com/crowdsecurity/cs-firewall-bouncer/issues/368>
* <https://bugs.launchpad.net/ubuntu/+source/crowdsec-firewall-bouncer/+bug/2069596>
* <https://github.com/google/nftables/commit/d746ecb0e494e7200180c3886fde9664d9100729>
