CVE-2024-1086
Last modified
CVE-2024-1086 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.. CISA has confirmed active exploitation in the wild. EPSS estimates a 28.06% chance of exploitation in the next 30 days.
Description
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Netapp | H300s Firmware | All versions | — |
| Netapp | H500s Firmware | All versions | — |
| Netapp | H700s Firmware | All versions | — |
| Netapp | H410s Firmware | All versions | — |
| Netapp | H410c Firmware | All versions | — |
| Netapp | Bootstrap Os | All versions | — |
| Linux | Linux Kernel | >= 3.15, < 5.15.149 | — |
| Linux | Linux Kernel | >= 6.1, < 6.1.76 | — |
| Linux | Linux Kernel | >= 6.2, < 6.6.15 | — |
| Linux | Linux Kernel | >= 6.7, < 6.7.3 | — |
| Linux | Linux Kernel | 6.8 | Rc1 |
| Fedoraproject | Fedora | 39 | — |
| Redhat | Enterprise Linux Desktop | 7.0 | — |
| Redhat | Enterprise Linux For Ibm Z Systems | 7.0_s390x | — |
| Redhat | Enterprise Linux For Power Big Endian | 7.0_ppc64 | — |
| Redhat | Enterprise Linux For Power Little Endian | 7.0_ppc64le | — |
| Redhat | Enterprise Linux Server | 7.0 | — |
| Redhat | Enterprise Linux Workstation | 7.0 | — |
| Debian | Debian Linux | 10.0 | — |
| Netapp | A250 Firmware | All versions | — |
| Netapp | 500f Firmware | All versions | — |
| Netapp | C250 Firmware | All versions | — |
References
- http://www.openwall.com/lists/oss-security/2024/04/10/22Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2024/04/10/23Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2024/04/14/1Exploit, Mailing List
- http://www.openwall.com/lists/oss-security/2024/04/17/5Exploit, Mailing List
- https://github.com/Notselwyn/CVE-2024-1086Exploit, Third Party Advisory
- https://news.ycombinator.com/item?id=39828424Issue Tracking
- https://pwning.tech/nftables/Exploit, Technical Description, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240614-0009/Third Party Advisory
- http://www.openwall.com/lists/oss-security/2024/04/10/22Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2024/04/10/23Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2024/04/14/1Exploit, Mailing List
- http://www.openwall.com/lists/oss-security/2024/04/17/5Exploit, Mailing List
- https://github.com/Notselwyn/CVE-2024-1086Exploit, Third Party Advisory
- https://news.ycombinator.com/item?id=39828424Issue Tracking
- https://pwning.tech/nftables/Exploit, Technical Description, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240614-0009/Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1086US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-1086?
How severe is CVE-2024-1086?
How do I fix CVE-2024-1086?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-10853The Buy one click WooCommerce plugin for WordPress is vulner…4.3
- CVE-2024-10854The Buy one click WooCommerce plugin for WordPress is vulner…4.3
- CVE-2024-10855The Image Optimizer, Resizer and CDN – Sirv plugin for WordP…8.1
- CVE-2024-10856The Booking Calendar WpDevArt plugin is vulnerable to time-b…6.5
- CVE-2024-10857The Product Input Fields for WooCommerce plugin for WordPres…6.5
- CVE-2024-10858The Jetpack WordPress plugin before 14.1 does not properly …6.1
- CVE-2024-10860The NextMove Lite – Thank You Page for WooCommerce plugin fo…4.3
- CVE-2024-10861The Popup Box – Create Countdown, Coupon, Video, Contact For…5.3
- CVE-2024-10862The NEX-Forms – Ultimate Form Builder – Contact forms and mu…4.9
- CVE-2024-10863: Insufficient Logging vulnerability in OpenText Secure Cont…5.1
- CVE-2024-10864Improper Neutralization of Special Elements used in an SQL C…7.5
- CVE-2024-10865Improper Input validation leads to XSS or Cross-site Scripti…9.4
Are you affected by CVE-2024-1086?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
