kernel CVE-2024-1086
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.19.2
Patched versions
1.19.2
kernel-5.15
(bottlerocket)
< 1.19.2
1.19.2
A use-after-free flaw was found in the Netfilter subsystem in the Linux kernel. Allowing positive values as a drop error in the nft_verdict_init() function can lead to a double free in nf_hook_slow() function. This can be used to achieve local privilege escalation.