EXPOSURES › CVE-2024-1086
CVE-2024-1086
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA use-after-free vulnerability in the Linux kernel's netfilter component allows local privilege escalation and has been actively exploited in the wild.
This Linux kernel vulnerability enables local privilege escalation, meaning an attacker with local access can escalate to root. DIB organizations must ensure their Linux systems are patched against this actively exploited CVE, as it represents a critical failure in the supply chain and ongoing maintenance of foundational OS components. Failure to patch exposes systems to ransomware and further compromise.
Shame score — The Linux kernel is a foundational component shipped by major vendors; a critical, actively exploited vulnerability in its core networking stack demonstrates severe negligence in patching and supply chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.