CVE-2024-1086
Use-after-free in Linux kernel's netfilter: nf_tables component
Description
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.
In plain language
AI Act nowCVE-2024-1086 is a Linux kernel bug (in netfilter’s nf_tables) that has been used in real ransomware, so if you run a vulnerable Linux kernel on a system exposed to attackers, you should patch urgently.
CVE-2024-1086 is a use-after-free in the Linux kernel netfilter nf_tables component that can be exploited (including in real-world ransomware activity) to gain higher privileges on affected systems; patch the kernel to the fixed versions identified by the vendor/security advisories.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2024-1086 and every CVE in our database. Create a free account — no credit card required.
Create Free Account