CISA has confirmed that ransomware groups are actively exploiting a high-severity privilege escalation vulnerability in the Linux kernel, tracked as CVE-2024-1086. This use-after-free flaw, present in the netfilter: nf_tables component and introduced in 2014, was patched in January 2024 but remains a significant risk for unpatched systems. Successful exploitation allows attackers with local access to escalate privileges to root, enabling full system takeover, disabling of security defenses, installation of malware, and lateral movement within networks. The vulnerability affects a wide range of major Linux distributions, including Debian, Ubuntu, Fedora, and Red Hat, across kernel versions from 3.15 to 6.8-rc1. In March 2024, a security researcher published a detailed proof-of-concept exploit, further increasing the risk of widespread exploitation.
CISA added CVE-2024-1086 to its Known Exploited Vulnerabilities (KEV) catalog in May 2024 and mandated that federal agencies secure affected systems by June 20, 2024. Despite the availability of a patch, ransomware campaigns have begun leveraging this flaw, though CISA has not disclosed specific threat actor identities or detailed attack campaigns. Security experts recommend immediate patching, or if not possible, implementing mitigations such as blocklisting 'nf_tables', restricting user namespace access, or loading the Linux Kernel Runtime Guard (LKRG) module. The public availability of exploit code and the broad impact across Linux environments underscore the urgency for organizations to address this vulnerability to prevent ransomware-driven compromise and data theft.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
CISA said CVE-2024-1086 is being actively exploited in ransomware intrusions, marking a renewed escalation in the threat. Reports noted that attackers had found reliable exploitation methods without triggering kernel panics, but CISA did not release IOCs or further technical details.
Following the KEV listing, CISA required federal civilian agencies to remediate or mitigate affected systems by June 20, 2024. Recommended measures included patching, blocklisting nf_tables, restricting user namespaces, or using LKRG where appropriate.
CISA added CVE-2024-1086 to its KEV catalog in May 2024 after confirming active exploitation. The agency warned that the bug posed significant risk to federal enterprises and other organizations.
A public proof-of-concept exploit for CVE-2024-1086 was released in March 2024, increasing the likelihood of real-world abuse. The exploit demonstrated how local attackers could obtain root privileges on affected systems.
Researcher Notselwyn identified and described the vulnerability and its exploitation characteristics, including difficulties reproducing the bug reliably. This public research helped clarify the impact on major Linux distributions.
The Linux kernel vulnerability CVE-2024-1086 was fixed in January 2024. The flaw was a high-severity use-after-free issue in netfilter's nf_tables component.
A Linux kernel commit introduced the nf_tables flaw later tracked as CVE-2024-1086. The bug affected kernel versions from 3.15 through 6.8-rc1 and enabled local privilege escalation to root.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.