CVE-2024-1086
Linux Kernel
Published 31 Jan 2024 · updated 7 Aug 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 30 May 2024, with a remediation deadline of 20 Jun 2024 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.
References
- www.openwall.com/lists/oss-security/2024/04/10/22 · Mailing List, Patch
- www.openwall.com/lists/oss-security/2024/04/10/23 · Mailing List, Patch
- www.openwall.com/lists/oss-security/2024/04/14/1 · Exploit, Mailing List
- www.openwall.com/lists/oss-security/2024/04/15/2 · Mailing List
- www.openwall.com/lists/oss-security/2024/04/17/5 · Exploit, Mailing List
- git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f342de4e2f33e0e39165d8639387aa6c19dff660 · Patch
- github.com/Notselwyn/CVE-2024-1086 · Exploit, Third Party Advisory
- kernel.dance/f342de4e2f33e0e39165d8639387aa6c19dff660 · Patch
- lists.debian.org/debian-lts-announce/2024/06/msg00016.html · Mailing List
- lists.debian.org/debian-lts-announce/2024/06/msg00020.html · Mailing List
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LSPIOMIJYTLZB6QKPQVVAYSUETUWKPF/ · Mailing List
- news.ycombinator.com/item?id=39828424 · Issue Tracking
- pwning.tech/nftables/ · Exploit, Technical Description, Third Party Advisory
- security.netapp.com/advisory/ntap-20240614-0009/ · Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1086 · US Government Resource