CISA Warns of Ransomware Exploiting CVE-2024-1086 in Linux Kernel

CISA Warns of Ransomware Exploiting CVE-2024-1086 in Linux Kernel

First seen 4 Nov 2025, 11:09 UTC BleepingcomputerThecyberexpressScworldWebpronews 39.3

Article Content

Browse articles
ThreatCluster

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding the exploitation of a critical vulnerability in the Linux kernel, tracked as CVE-2024-1086, by ransomware groups. This use-after-free flaw, located in the netfilter: nf_tables component, allows attackers with local access to escalate their privileges on affected systems. The vulnerability, first disclosed in January 2024, has been actively exploited despite being included in CISA's Known Exploited Vulnerabilities catalog over a year ago.

Ask AI about this cluster