Database/Kernel, userspace & hypervisor
Linux kernel (nf_tables): Use-after-free in nft_verdict_init() - double-free to local root
CVE-2024-1086Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Use-after-free in nft_verdict_init() - double-free to local root; weaponised public exploit with a very high success rate [KEV]
Who can reach it
Any tenant process in a container with CAP_NET_ADMIN in a userns
What to do
Livepatchable on supported kernels (Canonical/TuxCare/Ksplice all shipped it); otherwise drain + reboot. The single highest-priority container-escape CVE of the 2024 set - treat unpatched nodes as compromised-by-default in a shared-tenant fleet
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.