logo

Detecting CVE-2024-1086: The decade-old Linux kernel vulnerability that’s being actively exploited in ransomware campaigns

ID: d789975d-180f-5bf3-8a52-c2a0567084c0

STIX ID: report--d789975d-180f-5bf3-8a52-c2a0567084c0

Feed Name: Sysdig Blog

Threat Score
80/100

Date Published: 2025-11-20

Date Updated: 2026-05-01

...
...

This Sysdig Threat Research Team blog analyzes CVE-2024-1086, a decade-old double-free vulnerability in the Linux kernel netfilter (nftables) that can be exploited to gain root privileges. The report describes exploit mechanics (abusing unprivileged user namespaces, malformed SKBs, overwriting modprobe_path), lists affected kernel versions and patches, notes public PoC code and CISA confirmation of use in ransomware campaigns, and recommends urgent patching and runtime detection (Sysdig rules) to mitigate active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.