US government warns that Linux flaw is now being exploited for ransomware attacks



  • CVE-2024-1086, a Linux kernel flaw, is now exploited in active ransomware campaigns
  • The bug allows local privilege escalation and affects major distributions such as Ubuntu and Red Hat.
  • CISA urges patching or mitigation, warning of significant risk to federal and enterprise systems

The US government warns that a Linux flaw introduced more than a decade ago (and patched more than a year ago) is being actively used in ransomware attacks.

In February 2014, a vulnerability was introduced into the Linux kernel via a commit. The bug was first revealed in late January 2024 and was described as a “use-after-free weakness in the netfilter kernel component: nf_tables.” It was fixed later that month and assigned the tag CVE-2024-1086. Its severity score is 7.8/10 (high) and can be exploited to achieve local privilege escalation.



Leave a Comment

Your email address will not be published. Required fields are marked *