CISA warns of actively exploited Linux privilege elevation flaw
ID: ae7a12bc-b1c3-568a-b274-675938dc6920
STIX ID: report--ae7a12bc-b1c3-568a-b274-675938dc6920
Feed Name: Bleeping Computer
CISA added two known-exploited vulnerabilities to its KEV catalog with a June 20 mitigation deadline: CVE-2024-1086, a high-severity Linux nftables use-after-free that can yield local root via a public PoC and has been backported to many stable kernels, and CVE-2024-24919, an information disclosure in Check Point VPN devices; the report outlines affected versions, fixes, mitigations (blocklisting nf_tables, restricting user namespaces, LKRG), and notes public exploit discussion and delayed vendor patching that could enable exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
