CVE-2024-1086

KEV
🔴 Łataj teraz

Luka use-after-free w komponencie nf_tables jądra Linux umożliwia eskalację uprawnień lokalnych.

CVSS
7.8
EPSS
28.1%
Exploit
weaponized
Vendor
netapp
Opis źródłowy (NVD)

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.

exploit privilege-escalation Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.8
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)28.1%
Opublikowano (NVD)2024-01-31 13:15:10 UTC
Ostatnia modyfikacja (NVD)2026-08-07 19:59:58 UTC
Referencje