← Back

CVE-2024-1086

nvd nist
Published: Jan 31, 2024Modified: Oct 27, 2025CISA KEV

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.

Affected (16)

Show all products
1 product
Linux Kernel
1 product
Fedora
6 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Workstation
1 product
Debian Linux
3 products
A250 Firmware
500f Firmware
C250 Firmware
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 3.15 to 5.15.149
From 6.1 to 6.1.76
From 6.2 to 6.6.15
From 6.7 to 6.7.3
Version 6.8 rc1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 39
Configuration C
6 vulnerable
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
A250
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
500f
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
C250
All versions

References (29)

Source: cve-coordination@google.com
Mailing ListPatch
Source: cve-coordination@google.com
Mailing ListPatch
Source: cve-coordination@google.com
ExploitMailing List
Source: cve-coordination@google.com
Mailing List
Source: cve-coordination@google.com
ExploitMailing List
Source: cve-coordination@google.com
ExploitThird Party Advisory
Source: cve-coordination@google.com
Mailing List
Source: cve-coordination@google.com
Mailing List
Source: cve-coordination@google.com
Issue Tracking
Source: cve-coordination@google.com
ExploitTechnical DescriptionThird Party Advisory
Source: cve-coordination@google.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.