{"id":"CVE-2024-1086","title":"A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\n\n\nThe nft_verdict_init() function allows positive values as drop error within the hook verdict, …","summary":"A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\n\n\nThe nft_verdict_init() function allows positive values as drop error within the hook verdict, …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416","CWE-416"],"vendor":"netapp","product":"h300s_firmware","affected":["h300s_firmware","h500s_firmware","h700s_firmware","h410s_firmware","h410c_firmware","bootstrap_os","linux_kernel >= 3.15, < 5.15.149","linux_kernel >= 6.1, < 6.1.76","linux_kernel >= 6.2, < 6.6.15","linux_kernel >= 6.7, < 6.7.3","linux_kernel = 6.8","fedora = 39","enterprise_linux_desktop = 7.0","enterprise_linux_for_ibm_z_systems = 7.0_s390x","enterprise_linux_for_power_big_endian = 7.0_ppc64","enterprise_linux_for_power_little_endian = 7.0_ppc64le","enterprise_linux_server = 7.0","enterprise_linux_workstation = 7.0","debian_linux = 10.0","a250_firmware","500f_firmware","c250_firmware"],"patched":["linux_kernel 6.7.3"],"published":"2024-01-31","updated":"2026-08-07","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-1086","references":[{"url":"http://www.openwall.com/lists/oss-security/2024/04/10/22","label":"cve-coordination@google.com"},{"url":"http://www.openwall.com/lists/oss-security/2024/04/10/23","label":"cve-coordination@google.com"},{"url":"http://www.openwall.com/lists/oss-security/2024/04/14/1","label":"cve-coordination@google.com"},{"url":"http://www.openwall.com/lists/oss-security/2024/04/15/2","label":"cve-coordination@google.com"},{"url":"http://www.openwall.com/lists/oss-security/2024/04/17/5","label":"cve-coordination@google.com"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f342de4e2f33e0e39165d8639387aa6c19dff660","label":"cve-coordination@google.com"},{"url":"https://github.com/Notselwyn/CVE-2024-1086","label":"cve-coordination@google.com"},{"url":"https://kernel.dance/f342de4e2f33e0e39165d8639387aa6c19dff660","label":"cve-coordination@google.com"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html","label":"cve-coordination@google.com"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html","label":"cve-coordination@google.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LSPIOMIJYTLZB6QKPQVVAYSUETUWKPF/","label":"cve-coordination@google.com"},{"url":"https://news.ycombinator.com/item?id=39828424","label":"cve-coordination@google.com"},{"url":"https://pwning.tech/nftables/","label":"cve-coordination@google.com"},{"url":"https://security.netapp.com/advisory/ntap-20240614-0009/","label":"cve-coordination@google.com"},{"url":"http://www.openwall.com/lists/oss-security/2024/04/10/22","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2024/04/10/23","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2024/04/14/1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2024/04/15/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2024/04/17/5","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f342de4e2f33e0e39165d8639387aa6c19dff660","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/Notselwyn/CVE-2024-1086","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://kernel.dance/f342de4e2f33e0e39165d8639387aa6c19dff660","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LSPIOMIJYTLZB6QKPQVVAYSUETUWKPF/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://news.ycombinator.com/item?id=39828424","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://pwning.tech/nftables/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20240614-0009/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1086","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.28058,"epssPercentile":0.9807,"kev":true,"kevDateAdded":"2024-05-30","kevDueDate":"2024-06-20","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-07T20:16:40.392Z","exploits":{"github":17,"githubRepos":["https://github.com/Notselwyn/CVE-2024-1086","https://github.com/Alicey0719/docker-POC_CVE-2024-1086","https://github.com/CCIEVoice2009/CVE-2024-1086"],"checkedAt":"2026-09-21T15:26:15.815Z"},"exploitAvailable":true,"slug":"CVE-2024-1086","body":"## Overview\n\nA use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\n\n\nThe nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT.\n\n\n\nWe recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.\n\n## Affected\n\n- `h300s_firmware`\n- `h500s_firmware`\n- `h700s_firmware`\n- `h410s_firmware`\n- `h410c_firmware`\n- `bootstrap_os`\n- `linux_kernel >= 3.15, < 5.15.149`\n- `linux_kernel >= 6.1, < 6.1.76`\n- `linux_kernel >= 6.2, < 6.6.15`\n- `linux_kernel >= 6.7, < 6.7.3`\n- `linux_kernel = 6.8`\n- `fedora = 39`\n- `enterprise_linux_desktop = 7.0`\n- `enterprise_linux_for_ibm_z_systems = 7.0_s390x`\n- `enterprise_linux_for_power_big_endian = 7.0_ppc64`\n- `enterprise_linux_for_power_little_endian = 7.0_ppc64le`\n- `enterprise_linux_server = 7.0`\n- `enterprise_linux_workstation = 7.0`\n- `debian_linux = 10.0`\n- `a250_firmware`\n- `500f_firmware`\n- `c250_firmware`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.7.3`","depth":"abyssal","depthScore":79,"depthScoreParts":{"impact":42.9,"likelihood":5.6,"exploitation":25,"ransomware":5},"changes":[{"seq":4682,"id":"CVE-2024-1086","ts":1788887199614,"field":"exploit_available","old":"false","new":"true"},{"seq":3565,"id":"CVE-2024-1086","ts":1788886316106,"field":"exploit_available","old":"true","new":"false"},{"seq":2419,"id":"CVE-2024-1086","ts":1788882984878,"field":"exploit_available","old":"false","new":"true"},{"seq":1448,"id":"CVE-2024-1086","ts":1788882398125,"field":"exploit_available","old":"true","new":"false"},{"seq":562,"id":"CVE-2024-1086","ts":1788881834457,"field":"exploit_available","old":"false","new":"true"}]}