---
id: CVE-2024-1086
title: >-
  A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables
  component can be exploited to achieve local privilege escalation.




  The nft_verdict_init() function allows positive values as drop error within
  the hook verdict, …
summary: >-
  A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables
  component can be exploited to achieve local privilege escalation.




  The nft_verdict_init() function allows positive values as drop error within
  the hook verdict, …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
  - CWE-416
vendor: netapp
product: h300s_firmware
affected:
  - h300s_firmware
  - h500s_firmware
  - h700s_firmware
  - h410s_firmware
  - h410c_firmware
  - bootstrap_os
  - 'linux_kernel >= 3.15, < 5.15.149'
  - 'linux_kernel >= 6.1, < 6.1.76'
  - 'linux_kernel >= 6.2, < 6.6.15'
  - 'linux_kernel >= 6.7, < 6.7.3'
  - linux_kernel = 6.8
  - fedora = 39
  - enterprise_linux_desktop = 7.0
  - enterprise_linux_for_ibm_z_systems = 7.0_s390x
  - enterprise_linux_for_power_big_endian = 7.0_ppc64
  - enterprise_linux_for_power_little_endian = 7.0_ppc64le
  - enterprise_linux_server = 7.0
  - enterprise_linux_workstation = 7.0
  - debian_linux = 10.0
  - a250_firmware
  - 500f_firmware
  - c250_firmware
patched:
  - linux_kernel 6.7.3
published: '2024-01-31'
updated: '2026-08-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-1086'
references:
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/10/22'
    label: cve-coordination@google.com
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/10/23'
    label: cve-coordination@google.com
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/14/1'
    label: cve-coordination@google.com
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/15/2'
    label: cve-coordination@google.com
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/17/5'
    label: cve-coordination@google.com
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f342de4e2f33e0e39165d8639387aa6c19dff660
    label: cve-coordination@google.com
  - url: 'https://github.com/Notselwyn/CVE-2024-1086'
    label: cve-coordination@google.com
  - url: 'https://kernel.dance/f342de4e2f33e0e39165d8639387aa6c19dff660'
    label: cve-coordination@google.com
  - url: 'https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html'
    label: cve-coordination@google.com
  - url: 'https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html'
    label: cve-coordination@google.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LSPIOMIJYTLZB6QKPQVVAYSUETUWKPF/
    label: cve-coordination@google.com
  - url: 'https://news.ycombinator.com/item?id=39828424'
    label: cve-coordination@google.com
  - url: 'https://pwning.tech/nftables/'
    label: cve-coordination@google.com
  - url: 'https://security.netapp.com/advisory/ntap-20240614-0009/'
    label: cve-coordination@google.com
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/10/22'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/10/23'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/14/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/15/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/04/17/5'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f342de4e2f33e0e39165d8639387aa6c19dff660
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/Notselwyn/CVE-2024-1086'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kernel.dance/f342de4e2f33e0e39165d8639387aa6c19dff660'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LSPIOMIJYTLZB6QKPQVVAYSUETUWKPF/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://news.ycombinator.com/item?id=39828424'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://pwning.tech/nftables/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20240614-0009/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1086
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.28058
epssPercentile: 0.98023
kev: true
kevDateAdded: '2024-05-30'
kevDueDate: '2024-06-20'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-07T20:16:40.392Z'
exploits:
  github: 17
  githubRepos:
    - 'https://github.com/Notselwyn/CVE-2024-1086'
    - 'https://github.com/Alicey0719/docker-POC_CVE-2024-1086'
    - 'https://github.com/CCIEVoice2009/CVE-2024-1086'
  checkedAt: '2026-09-24T07:52:50.864Z'
exploitAvailable: true
---

## Overview

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.



The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT.



We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.

## Affected

- `h300s_firmware`
- `h500s_firmware`
- `h700s_firmware`
- `h410s_firmware`
- `h410c_firmware`
- `bootstrap_os`
- `linux_kernel >= 3.15, < 5.15.149`
- `linux_kernel >= 6.1, < 6.1.76`
- `linux_kernel >= 6.2, < 6.6.15`
- `linux_kernel >= 6.7, < 6.7.3`
- `linux_kernel = 6.8`
- `fedora = 39`
- `enterprise_linux_desktop = 7.0`
- `enterprise_linux_for_ibm_z_systems = 7.0_s390x`
- `enterprise_linux_for_power_big_endian = 7.0_ppc64`
- `enterprise_linux_for_power_little_endian = 7.0_ppc64le`
- `enterprise_linux_server = 7.0`
- `enterprise_linux_workstation = 7.0`
- `debian_linux = 10.0`
- `a250_firmware`
- `500f_firmware`
- `c250_firmware`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.7.3`
