CVE-2024-8038

Publication date 2 October 2024

Last updated 26 August 2025


Ubuntu priority

Cvss 3 Severity Score

7.9 · High

Score breakdown

Description

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.

Read the notes from the security team

Status


Notes


eslerm

CWE-420


lucistanescu

this affects the juju snap, no package in archive

Severity score breakdown

Parameter Value
Base score 7.9 · High
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Changed
Confidentiality Low
Integrity impact Low
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H