CVE-2024-26809 is a double-free vulnerability in the Linux kernel netfilter nftables pipapo set implementation. In affected kernels containing the pipapo commit-protocol integration, element-release handling could occur from the clone abort path as well as the destroy path. Because the clone already provides the current lookup-table view used for destruction, this could cause the same elements to be released twice. The fix limits clone element release to the destroy path.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small repository containing a standalone Linux local privilege escalation exploit written entirely in x86-64 NASM assembly. Structure is minimal: a Makefile to build the binary, a README describing usage, and a single large assembly source file (pintheft.asm) implementing the exploit logic. The exploit is not a framework module; it is a self-contained operational PoC. The README says it is a rewrite of a prior Go implementation and that it 'drops a root shell.' The assembly comments describe the exploit chain in detail: pin to CPU 0, locate a SUID target, back it up, map a page with guard space, register io_uring buffers with a +1024 bias, clone the buffer registration, fork a daemon, steal 1024 refs via RDS zero-copy, evict page cache with fadvise(DONTNEED), drain per-CPU page lists, unmap, pread, issue io_uring READ_FIXED, verify corruption, and finally execute via PTY. Core capabilities observed from the code and comments: - Local kernel exploitation using AF_RDS and io_uring primitives. - Refcount manipulation / dangling buffer abuse to obtain a page-cache overwrite primitive. - Discovery and backup of a SUID executable target. - Replacement of the target with an embedded minimal ELF payload. - Payload behavior is explicit: setuid(0) followed by execve('/bin/sh'). - Interactive shell handling via PTY-related ioctls. - Cleanup/operational usability features such as logging and printing a restore command for the overwritten SUID binary. Notable technical indicators include direct use of Linux syscalls for socket, bind, sendmsg, setsockopt, fadvise64, sched_setaffinity, memfd_create, and io_uring operations; constants for AF_RDS, SO_ZEROCOPY, SOL_RDS, IORING_REGISTER_BUFFERS, IORING_REGISTER_CLONE, and IORING_OP_READ_FIXED; and a hardcoded PORT_BASE of 20000. No external network infrastructure, remote C2, or hardcoded IP/domain endpoints are present. The exploit is purely local and targets the host kernel and local filesystem/SUID binaries rather than remote services. Overall, this repository's purpose is to provide a compact, low-level assembly implementation of a Linux kernel LPE exploit chain culminating in a root shell.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.