LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-1086: Linux Kernel Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 30, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 20, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-1086 to its Known Exploited Vulnerabilities catalog on May 30, 2024, with a federal patch deadline of Jun 20, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.

CVE-2024-1086 is a use-after-free vulnerability in the Linux kernel's netfilter nf_tables component. It allows a local attacker to escalate privileges on an affected system. Because the flaw sits in a core networking subsystem and has been tied to ransomware activity, it matters for any environment running Linux hosts that expose or rely on nf_tables functionality. Confirm exact impact and fixed versions against the vendor advisory.

Local privilege escalation can turn a foothold into full system control, enabling further lateral movement, persistence, or data access. Teams should treat this as a high-priority kernel issue requiring inventory and remediation.

How it works

The weakness is classified as CWE-416 (use-after-free). In the netfilter nf_tables component, memory that has already been freed can still be referenced under certain conditions. An attacker who can already execute code locally may trigger the condition to corrupt kernel memory and gain elevated privileges.

Abuse requires local access; the vulnerability does not itself provide remote code execution. Once privileges are escalated, the attacker can operate with kernel-level rights. Specific trigger sequences and exploit mechanics must be confirmed against the vendor advisory; do not rely on unvalidated public details.

Am I affected? How to find it in your systems

The vulnerability affects the Linux kernel. nf_tables is commonly present on modern distributions that use the nftables firewall framework, including servers, workstations, containers, and cloud images that load the relevant kernel modules.

How to remediate

Patch first. Apply the vendor-supplied kernel update that addresses CVE-2024-1086 as soon as it is available for your distribution. Follow the CISA-required action: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Reduce exposure until the patched kernel can be deployed.

If your data may have been exposed

Actively exploited vulnerabilities, including those known to be used by ransomware, frequently lead to breaches. If you believe an affected system was compromised, treat it as a potential incident: isolate the host, preserve logs and memory if possible, and follow your incident-response process. You can run a free exposure scan of your email address to check whether it appears in known breach data sets and take further account-protection steps as needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedLinux · Kernel
WeaknessCWE-416
Added to CISA KEVMay 30, 2024
Federal patch deadlineJun 20, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities