Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-32250

Опубликовано: 02 июн. 2022
Источник: debian
EPSS Низкий

Описание

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed5.18.2-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2022/05/31/1

  • https://git.kernel.org/linus/520778042ccca019f3ffa136dd0ca565c486cedd

  • Was previously also tracked as CVE-2022-1966

  • https://github.com/theori-io/CVE-2022-32250-exploit

  • https://research.nccgroup.com/2022/09/01/settlers-of-netlink-exploiting-a-limited-uaf-in-nf_tables-cve-2022-32250/

  • https://blog.theori.io/research/CVE-2022-32250-linux-kernel-lpe-2022/

EPSS

Процентиль: 83%
0.01996
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 3 лет назад

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

CVSS3: 7.8
redhat
около 3 лет назад

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

CVSS3: 7.8
nvd
около 3 лет назад

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

CVSS3: 7.8
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 7.8
github
около 3 лет назад

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

EPSS

Процентиль: 83%
0.01996
Низкий