Description
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5191-1 | linux security update |
Ubuntu USN |
USN-5540-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5544-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5545-1 | Linux kernel (OEM) vulnerability |
Ubuntu USN |
USN-5560-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5560-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5562-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5564-1 | Linux kernel (Intel IoTG) vulnerabilities |
Ubuntu USN |
USN-5566-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5582-1 | Linux kernel (Azure CVM) vulnerabilities |
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Linux
Subscribe
Linux Kernel
Subscribe
Netapp
Subscribe
H300s
Subscribe
H300s Firmware
Subscribe
H410c
Subscribe
H410c Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T09:22:10.749Z
Reserved: 2022-07-04T00:00:00.000Z
Link: CVE-2022-34918
No data.
Status : Modified
Published: 2022-07-04T21:15:07.730
Modified: 2024-11-21T07:10:26.080
Link: CVE-2022-34918
OpenCVE Enrichment
No data.
Debian DSA
Ubuntu USN