Related Vulnerabilities: CVE-2022-32250  

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

Description

The MITRE CVE dictionary describes this issue as:

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

Statement

This flaw was found to be a duplicate of CVE-2022-1966. Please see https://access.redhat.com/security/cve/CVE-2022-1966 for information about affected products and security errata.

This flaw was found to be a duplicate of CVE-2022-1966. Please see https://access.redhat.com/security/cve/CVE-2022-1966 for information about affected products and security errata.

Additional Information

  • Bugzilla 2093146: CVE-2022-32250 kernel: netfilter: nf_tables: incorrect NFT_STATEFUL_EXPR check leads to a use-after-free (write)
  • CWE-416: Use After Free
  • FAQ: Frequently asked questions about CVE-2022-32250