Apply vendor patches from Linux distribution maintainers immediately. Follow CISA emergency directive requirements for federal agencies. Employ compensating controls if immediate patching is not feasible. Monitor systems for indicators of compromise.
Quick answers
What is CVE-2024-1085?
Apply vendor patches from Linux distribution maintainers immediately. Follow CISA emergency directive requirements for federal agencies. Employ compensating controls if immediate patching is not feasible. Monitor systems for indicators of compromise.
How severe is CVE-2024-1085?
critical
Is CVE-2024-1085 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2024-1085 be mitigated?
Apply vendor patches from Linux distribution maintainers immediately. Follow CISA emergency directive requirements for federal agencies. Employ compensating controls if immediate patching is not feasible. Monitor systems for indicators of compromise.
CVSS
—
Vendor
—
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Linux kernel
Mitigation
Apply vendor patches from Linux distribution maintainers immediately. Follow CISA emergency directive requirements for federal agencies. Employ compensating controls if immediate patching is not feasible. Monitor systems for indicators of compromise.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation in the wild. One of the flaws is rated critical and may allow privilege escalation or remote code execution. The agency has issued an emergency directive requiring federal civilian executive branch agencies to patch affected systems within a defined timeframe. The vulnerabilities affect the Linux kernel across multiple distributions, with patches expected from maintainers.