Old Linux Kernel flaw CVE-2024-1086 resurfaces in ransomware attacks
好的,我现在要帮用户总结一篇文章的内容,控制在100个字以内。首先,我需要仔细阅读文章,理解其主要内容。 文章标题提到旧的Linux内核漏洞CVE-2024-1086被用于勒索软件攻击。CISA警告说,这个漏洞是在2014年引入的,直到2024年1月才被修补。这个漏洞属于高危级别,存在于netfilter: nf_tables组件中,允许攻击者进行本地权限提升。 接下来,文章提到研究人员Notselwyn在2024年3月发布了详细的分析和PoC代码,CISA随后将该漏洞加入到已知被利用的漏洞目录中。该漏洞影响多个主要Linux发行版,包括Debian、Ubuntu、Fedora和Red Hat。 用户的要求是用中文总结内容,控制在100字以内,并且不需要特定的开头。因此,我需要提取关键信息:漏洞名称、影响范围、攻击类型、发布者和影响版本。 现在,将这些信息整合成简洁的句子。确保不超过字数限制,并且准确传达主要点。 </think> CISA警告称,勒索软件团伙正在利用Linux内核漏洞CVE-2024-1086发起攻击,该漏洞于2014年引入,2024年1月修复,可导致本地权限提升,影响多个Linux发行版。 2025-10-31 18:11:45 Author: securityaffairs.com(查看原文) 阅读量:8 收藏

Old Linux Kernel flaw CVE-2024-1086 resurfaces in ransomware attacks

CISA warns ransomware gangs exploit CVE-2024-1086, a Linux kernel flaw in netfilter: nf_tables, introduced in 2014 and patched in Jan 2024.

CISA warned that ransomware gangs are exploiting CVE-2024-1086, a high-severity Linux kernel flaw introduced in 2014 and patched in January 2024.

CISA didn’t provide details about the ransomware attacks exploiting the flaw or name the groups responsible for targeting it.

The vulnerability CVE-2024-1086 is a Linux kernel use-after-free issue that resides in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.

In March 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog after the researcher “Notselwyn” published a detailed analysis and PoC exploit for the issue.

“When you try to reproduce the bug yourselves, the kernel may panic, even when all mitigations are disabled. This is because certain fields of the skb – such as pointers – get corrupted when the skb is freed. As such, we should try to avoid usage of these fields.” wrote Notselwyn. “Fortunately, I found a way to bypass all usage which could lead to a panic or usual errors and get a highly reliable double-free primitive. I’m highlighting this in the respective subsection within the proof-of-concept section.”

The researchers demonstrated local privilege escalation on Linux kernels 5.14–6.6. The flaw affects major distributions like Debian, Ubuntu, Fedora, and Red Hat, impacting kernel versions from 3.15 up to 6.8-rc1.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)




文章来源: https://securityaffairs.com/184076/security/old-linux-kernel-flaw-cve-2024-1086-resurfaces-in-ransomware-attacks.html
如有侵权请联系:admin#unsafe.sh