Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching
ID: 5797bbef-31a3-56e5-abc7-091d42371f80
STIX ID: report--5797bbef-31a3-56e5-abc7-091d42371f80
Feed Name: The Register (Security)
A critical local privilege‑escalation vulnerability (CVE-2024-1086) in the Linux kernel's netfilter (nf_tables) double-free allows unprivileged users to obtain root; a public proof-of-concept and detailed technical write-up (including the "Dirty Pagedirectory" memory corruption technique) are available, the flaw affects kernels roughly from 5.14 to 6.6.14 with a reported ~99.4% PoC success on some versions, and although upstream patches were released in late January, unpatched systems (default unprivileged user namespaces enabled on many distributions) remain at high risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
