CVE-2024-1086 KEV
7.8
HIGH · CVSS 3.1 · EPSS 28.1% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2024-06-20.
Description
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 28.06% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | yes — remediate by 2024-06-20 |
| Public exploit | none known |
| Published | 2024-01-31 |
| Last modified | 2026-08-07 |
CISA KEV
| Name | Linux Kernel Use-After-Free Vulnerability |
|---|---|
| Added | 2024-05-30 |
| Due | 2024-06-20 |
| Vendor / product | Linux / Kernel |
| Ransomware use | known |
Affected (27)
| Vendor | Product |
|---|---|
| debian | debian linux |
| fedoraproject | fedora |
| linux | linux kernel |
| netapp | 500f |
| netapp | 500f firmware |
| netapp | a250 |
| netapp | a250 firmware |
| netapp | bootstrap os |
| netapp | c250 |
| netapp | c250 firmware |
| netapp | h300s |
| netapp | h300s firmware |
| netapp | h410c |
| netapp | h410c firmware |
| netapp | h410s |
| netapp | h410s firmware |
| netapp | h500s |
| netapp | h500s firmware |
| netapp | h700s |
| netapp | h700s firmware |
| netapp | hci compute node |
| redhat | enterprise linux desktop |
| redhat | enterprise linux for ibm z systems |
| redhat | enterprise linux for power big endian |
| redhat | enterprise linux for power little endian |
| redhat | enterprise linux server |
| redhat | enterprise linux workstation |
References
- http://www.openwall.com/lists/oss-security/2024/04/10/22
- http://www.openwall.com/lists/oss-security/2024/04/10/23
- http://www.openwall.com/lists/oss-security/2024/04/14/1
- http://www.openwall.com/lists/oss-security/2024/04/15/2
- http://www.openwall.com/lists/oss-security/2024/04/17/5
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f342de4e2f33e0e39165d8639387aa6c19dff660
- https://github.com/Notselwyn/CVE-2024-1086
- https://kernel.dance/f342de4e2f33e0e39165d8639387aa6c19dff660
- https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LSPIOMIJYTLZB6QKPQVVAYSUETUWKPF/
- https://news.ycombinator.com/item?id=39828424
- https://pwning.tech/nftables/
- https://security.netapp.com/advisory/ntap-20240614-0009/
- http://www.openwall.com/lists/oss-security/2024/04/10/22
- http://www.openwall.com/lists/oss-security/2024/04/10/23
- http://www.openwall.com/lists/oss-security/2024/04/14/1
- http://www.openwall.com/lists/oss-security/2024/04/15/2
- http://www.openwall.com/lists/oss-security/2024/04/17/5
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f342de4e2f33e0e39165d8639387aa6c19dff660
→ the Explorer · watch your stack · NVD