• Menu
  • Skip to main content
  • Skip to primary sidebar

All Tech News

Latest Technology News

CISA Alerts Federal Agencies to Patch Actively Exploited Linux Kernel Flaw

You are here: Home / Cyber Security News / CISA Alerts Federal Agencies to Patch Actively Exploited Linux Kernel Flaw

The U.S. Cybersecurity and Infrastructure Security Company (CISA) on Thursday added a security flaw impacting the Linux kernel to the Recognised Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

Tracked as CVE-2024-1086 (CVSS rating: 7.8), the higher-severity issue relates to a use-soon after-cost-free bug in the netfilter part that permits a neighborhood attacker to elevate privileges from a regular user to root and quite possibly execute arbitrary code.

“Linux kernel incorporates a use-following-free vulnerability in the netfilter: nf_tables component that enables an attacker to accomplish nearby privilege escalation,” CISA reported.

Netfilter is a framework presented by the Linux kernel that allows the implementation of various network-related functions in the kind of personalized handlers to aid packet filtering, network deal with translation, and port translation.

The vulnerability was resolved in January 2024. That explained, the exact character of the attacks exploiting the flaw is presently unknown.

Also extra to the KEV catalog is a freshly disclosed security flaw impacting Look at Issue network gateway security goods (CVE-2024-24919, CVSS score: 7.5) that lets an attacker to read sensitive facts on Internet-related Gateways with distant obtain VPN or mobile accessibility enabled.

In light of the active exploitation of CVE-2024-1086 and CVE-2024-24919, federal organizations are advised to apply the most up-to-date fixes by June 20, 2024, to defend their networks against opportunity threats.

Identified this write-up exciting? Abide by us on Twitter  and LinkedIn to read through additional exceptional content we publish.

Some parts of this article are sourced from:
thehackernews.com

Previous Post: « FlyingYeti Exploits WinRAR Vulnerability to Deliver COOKBOX Malware in Ukraine
Next Post: OpenAI, Meta, TikTok Disrupt Multiple AI-Powered Disinformation Campaigns »

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • New Malware Campaign Uses Cloudflare Tunnels to Deliver RATs via Phishing Chains
  • 1,500+ Minecraft Players Infected by Java Malware Masquerading as Game Mods on GitHub
  • FedRAMP at Startup Speed: Lessons Learned
  • Water Curse Hijacks 76 GitHub Accounts to Deliver Multi-Stage Malware Campaign
  • Ex-CIA Analyst Sentenced to 37 Months for Leaking Top Secret National Defense Documents

Copyright © 2025 · AllTech.News, All Rights Reserved.