CISA: High-severity Linux flaw now exploited by ransomware gangs
ID: d70e40de-41a3-5e75-a463-5f334ced378a
STIX ID: report--d70e40de-41a3-5e75-a463-5f334ced378a
Feed Name: Bleeping Computer
Threat Score
A high-severity Linux kernel use-after-free vulnerability (CVE-2024-1086) in netfilter:nf_tables — introduced in 2014 and fixed in January 2024 — enables local privilege escalation to root. Public PoC exploit code was published and CISA confirmed the flaw is being leveraged in ransomware campaigns, added it to the Known Exploited Vulnerabilities catalog, and issued mitigation/patching guidance for affected distributions and kernel versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
