CISA KEV · Known exploitedHigh

CVE-2024-1086

Linux Kernel

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.

CVSS
7.8
EPSS
28.1%
97.9% percentile
CISA KEV
Listed
Published
2024.01.31
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability28.1%
Technical severityCVSS 7.8

Vulnerability overview

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.

Affected product and versions

Product
Linux Kernel
Affected versions
3.15, >= 3.15 < 5.15.149, >= 6.1 < 6.1.76, >= 6.2 < 6.6.15, >= 6.7 < 6.7.3, 6.8, 39, 7.0, 7.0 s390x, 7.0 ppc64, 7.0 ppc64le, 10.0
Fixed versions
5.15.149, 6.1.76, 6.6.15, 6.7.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Due date: 2024.06.20
  1. 1
    Identify

    Confirm that Linux Kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
KEV added
2024.05.30
Ransomware use
확인됨