Skip to main content
CISA Known Exploited Vulnerabilities

Linux Kernel Use-After-Free Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2024-06-26
Remediation due
2024-07-17

Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CISA notes
This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://seclists.org/oss-sec/2022/q3/131; https://nvd.nist.gov/vuln/detail/CVE-2022-2586

Description

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

Severity

CVSS 3.1 · CNA5.3 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H
SSVC · CISA-ADP
Exploitationactive
Automatableno
Technical impacttotal

Affected Products

VendorProductAffected versions
The Linux Kernel Organizationlinux
3.16 to <4.14.316
4.15 to <4.19.256
4.20 to <5.4.211
5.5 to <5.10.137
5.11 to <5.15.61
5.16 to <5.18.18
5.19 to <5.19.2

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CWE-416 · Use After Free

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.