logo

Detecting CVE-2024-1086: The decade-old Linux kernel vulnerability that’s being actively exploited in ransomware campaigns

ID: e129f242-cd60-50ed-b368-27883db81c4c

STIX ID: report--e129f242-cd60-50ed-b368-27883db81c4c

Feed Name: Sysdig Blog

Threat Score
78/100

Date Published: 2025-11-20

Date Updated: 2026-05-01

...
...

This report details CVE-2024-1086, a decade-old use-after-free vulnerability in the Linux kernel nftables component that allows privilege escalation to root; it is actively exploited (CISA-listed) in ransomware campaigns, has public PoC code, affects many kernel versions (notably v5.14–v6.6), and requires prompt patching and runtime detection to mitigate risks such as defense evasion, lateral movement, and system-wide encryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.