← Browse

CVE-2024-1086

Act now ● On CISA KEV — actively exploited used in ransomware

Actively exploited — on the CISA KEV list.

CVSS base
7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
28.1%
98.0th percentile
CISA KEV
Listed
Added 2024-05-30 · patch by 2024-06-20
Weakness / dates
CWE-416
Published 2024-01-31 · modified 2026-08-07

CVSS breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorLLocal
Attack ComplexityLLow
Privileges RequiredLLow
User InteractionNNone
ScopeUUnchanged
ConfidentialityHHigh
IntegrityHHigh
AvailabilityHHigh

Timeline

Description

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.

Affected

debian fedoraproject linux netapp redhat

References

Official: NVD · CVE.org