A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
The nftverdictinit() function allows positive values as drop error within the hook verdict, and hence the nfhookslow() function can cause a double free vulnerability when NFDROP is issued with a drop error which resembles NFACCEPT.
We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-1086.json"
[
{
"events": [
{
"introduced": "3.15"
},
{
"fixed": "5.15.149"
}
]
},
{
"events": [
{
"introduced": "6.1"
},
{
"fixed": "6.1.76"
}
]
},
{
"events": [
{
"introduced": "6.2"
},
{
"fixed": "6.6.15"
}
]
},
{
"events": [
{
"introduced": "6.7"
},
{
"fixed": "6.7.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.8-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "39"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0_ppc64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.0"
}
]
}
]