CVE-2022-32250
published 2022-06-02CVE-2022-32250: net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root…
PriorityP347high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
2.88%
85.3th percentile
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 5.18.2-1 (bookworm) | linux 5.18.2-1 (bookworm) |
| debian | linux | < linux 5.18.14-1 (bookworm) | linux 5.18.14-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | >= 0 < 5.10.127-2 | 5.10.127-2 |
| linux | linux_kernel | >= 0 < 5.10.120-1 | 5.10.120-1 |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 0 < 5.18.2-1 | 5.18.2-1 |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 0 < 5.18.2-1 | 5.18.2-1 |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 0 < 5.18.2-1 | 5.18.2-1 |
| linux | linux_kernel | >= 4.1 < 4.14.316 | 4.14.316 |
| linux | linux_kernel | >= 4.1 < 4.9.318 | 4.9.318 |
| linux | linux_kernel | >= 4.10 < 4.14.283 | 4.14.283 |
| linux | linux_kernel | >= 4.15 < 4.19.284 | 4.19.284 |
| linux | linux_kernel | >= 4.15 < 4.19.247 | 4.19.247 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9v26-h3ph-p8v7: An issue was discovered in the Linux kernel through 5
ghsa_unreviewed·2022-07-05·CVSS 7.8
CVE-2022-34918 [HIGH] CWE-843 GHSA-9v26-h3ph-p8v7: An issue was discovered in the Linux kernel through 5
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.
OSV
CVE-2022-34918: An issue was discovered in the Linux kernel through 5
osv·2022-07-04·CVSS 7.8
CVE-2022-34918 [HIGH] CVE-2022-34918: An issue was discovered in the Linux kernel through 5
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.
GHSA
GHSA-rv6g-4442-j26r: net/netfilter/nf_tables_api
ghsa_unreviewed·2022-06-03
CVE-2022-32250 [HIGH] CWE-416 GHSA-rv6g-4442-j26r: net/netfilter/nf_tables_api
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
OSV
CVE-2022-32250: net/netfilter/nf_tables_api
osv·2022-06-02·CVSS 7.8
CVE-2022-32250 [HIGH] CVE-2022-32250: net/netfilter/nf_tables_api
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
VulnCheck
Linux Kernel Access of Resource Using Incompatible Type ('Type Confusion')
vulncheck·2022·CVSS 7.8
CVE-2022-34918 [HIGH] Linux Kernel Access of Resource Using Incompatible Type ('Type Confusion')
Linux Kernel Access of Resource Using Incompatible Type ('Type Confusion')
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.
Affected: Linux Kernel
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://securelist.com/vulnerabilities-and-exploits-in-q4-2024/115761/
Exploit
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
CISA ICS
Siemens SIMATIC S7-1500 TM MFP Linux Kernel
cisa_ics·2023-06-15·CVSS 5.5
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP Linux Kernel
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP Linux Kernel
Release DateJune 15, 2023
Alert CodeICSA-23-166-11
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity / public exploits available
- Vendor: Siemens ProductCERT
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Multiple vulnerabilities
## 2. RISK EVALUATION
Exploitation of these vulnerabilities could lead to denial-of-service, crashing t
Microsoft
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges a differen
vendor_msrc·2022-07-12·CVSS 7.8
CVE-2022-34918 [HIGH] CWE-843 An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges a differen
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges a different vulnerability than CVE-2022-32250. (The attacker can obtain root access but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the dis
Red Hat
kernel: heap overflow in nft_set_elem_init()
vendor_redhat·2022-07-02·CVSS 7.8
CVE-2022-34918 [HIGH] CWE-1025 kernel: heap overflow in nft_set_elem_init()
kernel: heap overflow in nft_set_elem_init()
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.
A heap buffer overflow flaw was found in the Linux kernel’s Netfilter subsystem in the way a user provides incorrect input of the NFT_DATA_VERDICT type. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Mitigation: In order to trigger the issue, it requires the ability
Microsoft
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check le
vendor_msrc·2022-06-14·CVSS 7.8
CVE-2022-32250 [HIGH] CWE-416 net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check le
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identi
Red Hat
kernel: netfilter: nf_tables: incorrect NFT_STATEFUL_EXPR check leads to a use-after-free (write)
vendor_redhat·2022-06-02·CVSS 7.8
CVE-2022-1966 [HIGH] CWE-416 kernel: netfilter: nf_tables: incorrect NFT_STATEFUL_EXPR check leads to a use-after-free (write)
kernel: netfilter: nf_tables: incorrect NFT_STATEFUL_EXPR check leads to a use-after-free (write)
[REJECTED CVE] A use-after-free vulnerability has been identified in the Linux Kernel's netfilter subsystem that did not properly handle the removal of stateful expressions in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.
Statement: This CVE has been rejected. This candidate is a duplicate of CVE-2022-32250. Note: All CVE users should reference CVE-2022-32250 instead of this candidate.
Package: kernel (Red Hat Enterprise Linux 6) - Under investigation
Package: kernel (Red Hat Enterprise Linux 8) - Under investigation
Package: kernel-rt (Red Hat Enterprise Linux 8) - Under investigation
Red Hat
kernel: a use-after-free write in the netfilter subsystem can lead to privilege escalation to root
vendor_redhat·2022-05-31·CVSS 7.8
CVE-2022-32250 [HIGH] CWE-416 kernel: a use-after-free write in the netfilter subsystem can lead to privilege escalation to root
kernel: a use-after-free write in the netfilter subsystem can lead to privilege escalation to root
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
A use-after-free vulnerability was found in the Linux kernel's Netfilter subsystem in net/netfilter/nf_tables_api.c. This flaw allows a local attacker with user access to cause a privilege escalation issue.
Statement: The latest kernel in RHCOS is kernel-4.18.0-305.49.1.el8 which does not contain the vulnerable code and is not affected, also OCP v4.9 or earlier are not affected.
Mitigation: In order to trigger the issue, it requires the ability to create user/net name
Debian
CVE-2022-32250: linux - net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local ...
vendor_debian·2022·CVSS 7.8
CVE-2022-32250 [HIGH] CVE-2022-32250: linux - net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local ...
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
Scope: local
bookworm: resolved (fixed in 5.18.2-1)
bullseye: resolved (fixed in 5.10.120-1)
forky: resolved (fixed in 5.18.2-1)
sid: resolved (fixed in 5.18.2-1)
trixie: resolved (fixed in 5.18.2-1)
Debian
CVE-2022-34918: linux - An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug...
vendor_debian·2022·CVSS 7.8
CVE-2022-34918 [HIGH] CVE-2022-34918: linux - An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug...
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.
Scope: local
bookworm: resolved (fixed in 5.18.14-1)
bullseye: resolved (fixed in 5.10.127-2)
forky: resolved (fixed in 5.18.14-1)
sid: resolved (fixed in 5.18.14-1)
trixie: resolved (fixed in 5.18.14-1)
No detection rules found.
No public exploits indexed.
arXiv
PortGPT: Towards Automated Backporting Using Large Language Models
arxiv_fulltext·2025-10-25
PortGPT: Towards Automated Backporting Using Large Language Models
: Towards Automated Backporting Using Large Language Models
Zhaoyang Li21,
Zheng Yu31,
Jingyi Song2,
Meng Xu5,
Yuxuan Luo6,
Dongliang Mu24
2School of Cyber Science and Engineering, Huazhong University of Science and Technology, China
2Hubei Key Laboratory of Distributed System Security
3Northwestern University,
5University of Waterloo,
6Canonical Ltd.,
4JinYinHu Laboratory, China
\lizy04, jingyisong, dzm91\@hust.edu.cn
[email protected],
[email protected],
[email protected]
\@makefntext#1 1em #1
1 The first two authors contributed equally (alphabetical order).
Corresponding author
## Abstract
Patch backporting,
the process of migrating mainline security patches to older branches,
is an essential task in maintaining popular open-source projects
(e.g., Linux ke
arXiv
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
arxiv_fulltext·2024-09-24
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
Bonan Ruan
National University of Singapore
Jiahao Liu
National University of Singapore
Chuqi Zhang
National University of Singapore
Zhenkai Liang
National University of Singapore
## Abstract
Linux kernel vulnerability reproduction is a critical task in system security.
To reproduce a kernel vulnerability, the vulnerable environment and the Proof of Concept (PoC) program are needed.
Most existing research focuses on the generation of PoC, while the construction of environment is overlooked.
However, establishing an effective vulnerable environment to trigger a vulnerability is challenging.
Firstly, it is hard to guarantee that the selected kernel version for reproduction is vulnerable, as the vulner
arXiv
S2malloc: Statistically Secure Allocator for Use-After-Free Protection And More
arxiv_fulltext·2024-05-29
S2malloc: Statistically Secure Allocator for Use-After-Free Protection And More
: Statistically Secure Allocator for Use-After-Free Protection And More
Ruizhe Wang0009-0001-5607-3917
Meng Xu0009-0001-6364-4837
N. Asokan0000-0002-5093-9871
R. Wang et al.
University of Waterloo
\ruizhe.wang, meng.xu.cs\@uwaterloo.ca [email protected]
## Abstract
Attacks on heap memory, encompassing
memory overflow,
double and invalid free,
use-after-free (UAF),
and
various heap spraying techniques
are ever-increasing.
Existing entropy-based secure
memory allocators provide statistical defenses
against virtually all of these attack vectors.
Although they claim protections against UAF attacks,
their designs are not tailored to detect
(failed) attempts.
Consequently,
to beat this entropy-based protection,
an attacker can simply launch the same attack repeatedly
with the potential use
http://www.openwall.com/lists/oss-security/2022/06/03/1http://www.openwall.com/lists/oss-security/2022/06/04/1http://www.openwall.com/lists/oss-security/2022/06/20/1http://www.openwall.com/lists/oss-security/2022/07/03/5http://www.openwall.com/lists/oss-security/2022/07/03/6http://www.openwall.com/lists/oss-security/2022/08/25/1http://www.openwall.com/lists/oss-security/2022/09/02/9https://blog.theori.io/research/CVE-2022-32250-linux-kernel-lpe-2022/https://bugzilla.redhat.com/show_bug.cgi?id=2092427https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/net/netfilter?id=520778042ccca019f3ffa136dd0ca565c486ceddhttps://github.com/theori-io/CVE-2022-32250-exploithttps://lists.debian.org/debian-lts-announce/2022/07/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MO6Y3TC4WUUNKRP7OQA26OVTZTPCS6F2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UIZTJOJCVVEJVOQSCHE6IJQKMPISHQ5L/https://security.netapp.com/advisory/ntap-20220715-0005/https://www.debian.org/security/2022/dsa-5161https://www.debian.org/security/2022/dsa-5173https://www.openwall.com/lists/oss-security/2022/05/31/1http://www.openwall.com/lists/oss-security/2022/06/03/1http://www.openwall.com/lists/oss-security/2022/06/04/1http://www.openwall.com/lists/oss-security/2022/06/20/1http://www.openwall.com/lists/oss-security/2022/07/03/5http://www.openwall.com/lists/oss-security/2022/07/03/6http://www.openwall.com/lists/oss-security/2022/08/25/1http://www.openwall.com/lists/oss-security/2022/09/02/9https://blog.theori.io/research/CVE-2022-32250-linux-kernel-lpe-2022/https://bugzilla.redhat.com/show_bug.cgi?id=2092427https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/net/netfilter?id=520778042ccca019f3ffa136dd0ca565c486ceddhttps://github.com/theori-io/CVE-2022-32250-exploithttps://lists.debian.org/debian-lts-announce/2022/07/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MO6Y3TC4WUUNKRP7OQA26OVTZTPCS6F2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UIZTJOJCVVEJVOQSCHE6IJQKMPISHQ5L/https://security.netapp.com/advisory/ntap-20220715-0005/https://www.debian.org/security/2022/dsa-5161https://www.debian.org/security/2022/dsa-5173https://www.openwall.com/lists/oss-security/2022/05/31/1
2022-06-02
Published