GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel (nf_tables): Use-after-free in nft_verdict_init() - double-free to local root

CVE-2024-1086Kernel, userspace & hypervisorKnown exploitedcurated

Impact

Use-after-free in nft_verdict_init() - double-free to local root; weaponised public exploit with a very high success rate [KEV]

Who can reach it

Any tenant process in a container with CAP_NET_ADMIN in a userns

What to do

Livepatchable on supported kernels (Canonical/TuxCare/Ksplice all shipped it); otherwise drain + reboot. The single highest-priority container-escape CVE of the 2024 set - treat unpatched nodes as compromised-by-default in a shared-tenant fleet

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.