More

    Old Linux Kernel flaw CVE-2024-1086 resurfaces in ransomware attacks

    Pierluigi Paganini
    October 31, 2025

    CISA warned that ransomware gangs are exploiting CVE-2024-1086, a high-severity Linux kernel flaw introduced in 2014 and patched in January 2024.

    CISA didn’t provide details about the ransomware attacks exploiting the flaw or name the groups responsible for targeting it.

    The vulnerability CVE-2024-1086 is a Linux kernel use-after-free issue that resides in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.

    In Mat 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog after the researcher “Notselwyn” published a detailed analysis and PoC exploit for the issue. The researchers demonstrated local privilege escalation on Linux kernels 5.14–6.6. The flaw affects major distributions like Debian, Ubuntu, Fedora, and Red Hat, impacting kernel versions from 3.15 up to 6.8-rc1.

    Follow me on Twitter: @securityaffairs and Facebook and Mastodon

    Pierluigi Paganini

    (SecurityAffairs – hacking, CISA)


    facebook
    linkedin
    twitter


    CVE-2024-1086
    Cybercrime
    Hacking
    hacking news
    information security news
    IT Information Security
    LINUX
    malware
    Pierluigi Paganini
    ransomware
    Security Affairs
    Security News

     

    Latest articles

    Related articles