Vulnerability record · CVE-2022-2586 · published 8 January 2024
CVE-2022-2586: Linux kernel nftables cross-table set reference use-after-free
Linux · Linux Kernel
A flaw in the Linux kernel nftables subsystem allows an nft object or expression to reference an nft set belonging to a different nft table. When that table is deleted, the dangling reference causes a use-after-free. This matters because it is a memory-corruption bug in a core kernel subsystem that is reachable by a local user with the ability to configure nftables.
Description
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a local kernel use-after-free with high CVSS impact and confirmed exploitation in CISA KEV, though it requires local low-privilege access rather than being remotely reachable.
What it is
A flaw in the Linux kernel nftables subsystem allows an nft object or expression to reference an nft set belonging to a different nft table. When that table is deleted, the dangling reference causes a use-after-free. This matters because it is a memory-corruption bug in a core kernel subsystem that is reachable by a local user with the ability to configure nftables.
Impact
An attacker who can trigger the dangling reference gains use-after-free access in kernel memory, which can lead to privilege escalation or code execution in kernel context, with high impact to confidentiality, integrity and availability.
Attack surface
The CVSS vector is local (AV:L), low complexity, low privileges required, and no user interaction, so it is reached by a local user who can create and delete nftables tables and sets. No remote or network vector is described.
Exploitation
CVE-2022-2586 is listed in CISA KEV with a due date of 2024-07-17, indicating known exploitation, and EPSS gives a 30-day probability of about 10.5 percent (95.5th percentile). CISA records no known ransomware campaign use.
What to do
- Apply the vendor kernel updates referenced in the Ubuntu security notices (USN-5557-1, USN-5560-1/2, USN-5562-1, USN-5564-1 through USN-5567-1, USN-5582-1) or the equivalent patched kernel for your distribution.
- If patching is not possible, restrict local access to nftables configuration to trusted users and remove unnecessary local accounts.
- Follow CISA KEV guidance: apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
- Track the upstream netfilter-devel patch thread for the fix and confirm your kernel build includes it.
- Audit systems where unprivileged or low-privilege local users can run nft commands.
Detection
- Monitor for local processes invoking nft to create sets in one table and delete the owning table shortly after, which is the trigger pattern for the dangling reference.
- Watch kernel logs for use-after-free, KASAN or slab corruption reports involving nftables or netfilter code paths.
- Alert on unexpected privilege escalation or suspicious kernel-level activity on hosts where nftables is configured by non-root or low-privilege users.
- Inventory kernel versions against the patched builds named in the Ubuntu security notices to find unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-2586 to the Known Exploited Vulnerabilities catalog on 26 June 2024 as "Linux Kernel Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 17 July 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-2586 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-2586), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.