Description
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.
Exploits (12)
nomisec
WORKING POC
2 stars
by Alicey0719 · poc
https://github.com/Alicey0719/docker-POC_CVE-2024-1086
References (15)
Scores
CVSS v3
7.8
EPSS
0.8675
EPSS Percentile
99.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Lab Environment
COMMUNITY
Community Lab
+9 more repos
Details
CISA KEV
2024-05-30
VulnCheck KEV
2024-05-30
InTheWild.io
2024-05-30
ENISA EUVD
EUVD-2024-16861
Ransomware Use
Confirmed
CWE
CWE-416
Status
published
Products (13)
debian/debian_linux
10.0
fedoraproject/fedora
39
linux/linux_kernel
6.8 rc1
linux/linux_kernel
3.15 - 5.15.149
netapp/500f_firmware
netapp/a250_firmware
netapp/c250_firmware
redhat/enterprise_linux_desktop
7.0
redhat/enterprise_linux_for_ibm_z_systems
7.0_s390x
redhat/enterprise_linux_for_power_big_endian
7.0_ppc64
... and 3 more
Published
Jan 31, 2024
KEV Added
May 30, 2024
Tracked Since
Feb 18, 2026