The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT.
We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Linux
Subscribe
|
Linux Kernel
Subscribe
|
|
Netapp
Subscribe
|
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux For Ibm Z Systems
Subscribe
Enterprise Linux For Power Big Endian
Subscribe
Enterprise Linux For Power Little Endian
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Workstation
Subscribe
Logging
Subscribe
Rhel Aus
Subscribe
Rhel E4s
Subscribe
Rhel Eus
Subscribe
Rhel Extras Rt
Subscribe
Rhel Tus
Subscribe
Rhev Hypervisor
Subscribe
|
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3840-1 | linux security update |
Debian DLA |
DLA-3841-1 | linux-5.10 security update |
Ubuntu USN |
USN-6688-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-6700-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6700-2 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-6701-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6701-2 | Linux kernel (GCP) vulnerabilities |
Ubuntu USN |
USN-6701-3 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6701-4 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-6702-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6702-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6704-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6704-2 | Linux kernel (Raspberry Pi) vulnerabilities |
Ubuntu USN |
USN-6704-3 | Linux kernel (Oracle) vulnerabilities |
Ubuntu USN |
USN-6704-4 | Linux kernel (Intel IoTG) vulnerabilities |
Ubuntu USN |
USN-6705-1 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-6707-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6707-2 | Linux kernel (ARM laptop) vulnerabilities |
Ubuntu USN |
USN-6707-3 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-6707-4 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-6716-1 | Linux kernel (Azure) vulnerabilities |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 21 Oct 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 14 Feb 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:linux:linux_kernel:3.15:*:*:*:*:*:*:* | |
| Metrics |
kev
|
Thu, 13 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660. | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660. |
Wed, 14 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Debian
Debian debian Linux Netapp Netapp 500f Netapp 500f Firmware Netapp a250 Netapp a250 Firmware Netapp c250 Netapp c250 Firmware |
|
| CPEs | cpe:2.3:h:netapp:500f:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:a250:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:c250:-:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:o:netapp:500f_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:c250_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Debian
Debian debian Linux Netapp Netapp 500f Netapp 500f Firmware Netapp a250 Netapp a250 Firmware Netapp c250 Netapp c250 Firmware |
Wed, 14 Aug 2024 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-10-21T23:05:25.720Z
Reserved: 2024-01-30T20:04:09.704Z
Link: CVE-2024-1086
Updated: 2024-08-01T18:26:30.467Z
Status : Analyzed
Published: 2024-01-31T13:15:10.827
Modified: 2025-10-27T17:06:37.437
Link: CVE-2024-1086
OpenCVE Enrichment
No data.
Debian DLA
Ubuntu USN