Skip to content

kernel CVE-2022-2586

Moderate
rpkelly published GHSA-j7qm-552q-93v3 Jan 27, 2023

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.12.0

Patched versions

1.12.0
kernel-5.15 (bottlerocket)
< 1.12.0
1.12.0

Description

A use-after-free flaw was found in nf_tables cross-table in the net/netfilter/nf_tables_api.c function in the Linux kernel. This flaw allows a local, privileged attacker to cause a use-after-free problem at the time of table deletion, possibly leading to local privilege escalation.

Severity

Moderate

CVE ID

CVE-2022-2586

Weaknesses

No CWEs