Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1966

Опубликовано: 02 июн. 2022
Источник: redhat

Описание

[REJECTED CVE] A use-after-free vulnerability has been identified in the Linux Kernel's netfilter subsystem that did not properly handle the removal of stateful expressions in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.

Отчет

This CVE has been rejected. This candidate is a duplicate of CVE-2022-32250. Note: All CVE users should reference CVE-2022-32250 instead of this candidate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelUnder investigation
Red Hat Enterprise Linux 8kernelUnder investigation
Red Hat Enterprise Linux 8kernel-rtUnder investigation
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2022:523628.06.2022
Red Hat Enterprise Linux 7kpatch-patchFixedRHSA-2022:521628.06.2022
Red Hat Enterprise Linux 7kernelFixedRHSA-2022:523228.06.2022
Red Hat Enterprise Linux 8.2 Extended Update Supportkernel-rtFixedRHSA-2022:522428.06.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportkernelFixedRHSA-2022:522028.06.2022
Red Hat Enterprise Linux 8.2 Extended Update Supportkpatch-patchFixedRHSA-2022:547601.07.2022
Red Hat Enterprise Linux 9kernelFixedRHSA-2022:524901.07.2022

Показывать по

Дополнительная информация

Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2093146kernel: netfilter: nf_tables: incorrect NFT_STATEFUL_EXPR check leads to a use-after-free (write)

Связанные уязвимости

nvd
около 3 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-32250. Reason: This candidate is a duplicate of CVE-2022-32250. Notes: All CVE users should reference CVE-2022-32250 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

CVSS3: 7.8
github
около 3 лет назад

A use-after-free vulnerability was found in the Linux kernel's Netfilter subsystem in net/netfilter/nf_tables_api.c. This flaw allows a local attacker with user access to cause a privilege escalation issue.

CVSS3: 7.8
fstec
около 3 лет назад

Уязвимость компонента net/netfilter/nf_tables_api.c подсистемы netfilter ядра операционной системы Linux, позволяющая нарушителю повысить свои привилегии до уровня root

suse-cvrf
почти 3 года назад

Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP3)

oracle-oval
почти 3 года назад

ELSA-2022-5232: kernel security and bug fix update (IMPORTANT)