⚠ Actively exploited
Added to CISA KEV on 2024-06-26. Federal agencies required to patch by 2024-07-17. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable..

CVE-2022-2586

CWE-416Use After FreeCWE-82527 documents10 sources
Severity
7.8HIGH
EPSS
2.2%
top 15.52%
CISA KEV
KEV
Added 2024-06-26
Due 2024-07-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJan 8
KEV addedJun 26
KEV dueJul 17
Latest updateJun 18
CISA Required Action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

Description

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:HExploitability: 1.0 | Impact: 4.2

Affected Packages4 packages

CVEListV5linux/linux958bee14d0718ca7a5002c0f48a099d1d345812a77d3b5038b7462318f5183e2ad704b01d57215a2+7
Debianlinux< 5.10.136-1+3
NVDlinux/linux_kernel5.19.17+1

Also affects: Ubuntu Linux 14.04, 16.04, 18.04, 20.04, 22.04

Patches

🔴Vulnerability Details

11
CVEList
CVE-2022-2586: It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was2024-01-08
OSV
CVE-2022-2586: It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was2024-01-08
OSV
linux, linux-hwe-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15 vulnerabilities2022-08-10
OSV
linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gke-5.15, linux-ibm, linux-kvm, linux-oracle, linux-raspi vulnerabilities2022-08-10
OSV
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities2022-08-10

📋Vendor Advisories

15
Red Hat
kernel: netfilter: nf_tables: do not allow SET_ID to refer to another table2025-06-18
CISA
Linux Kernel Use-After-Free Vulnerability2024-06-26
Microsoft
It was discovered that a nft object or expression could reference a nft set on a different nft table leading to a use-after-free once that table was deleted.2024-01-09
Ubuntu
Linux kernel (Azure CVM) vulnerabilities2022-08-25
Ubuntu
Kernel Live Patch Security Notice2022-08-24
CVE-2022-2586 (HIGH CVSS 7.8) | It was discovered that a nft object | cvebase.io