THREATOPS
THREAT OPSThreat News › [NVD] CVE-2024-1086 (HIGH 7.8) — A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can c

[NVD] CVE-2024-1086 (HIGH 7.8) — A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can c

lownvdPublished 2024-01-31

CVE-2024-1086 CVSS: 7.8 HIGH Published: 2024-01-31T13:15:10.827

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.

The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-1086