← Vulnerability feed

Vulnerability record · CVE-2022-2586 · published 8 January 2024

CVE-2022-2586: Linux kernel nftables cross-table set reference use-after-free

Linux · Linux Kernel

A flaw in the Linux kernel nftables subsystem allows an nft object or expression to reference an nft set belonging to a different nft table. When that table is deleted, the dangling reference causes a use-after-free. This matters because it is a memory-corruption bug in a core kernel subsystem that is reachable by a local user with the ability to configure nftables.

7.8 CVSS 3.1 High CISA KEV since 26 Jun 2024 EPSS 10% · top 4.5% CWE-416 · Use after free
7.8CVSS 3.1 base score
10%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
28References, 1 tagged exploit
20 Aug 2026Last modified by NVD

Description

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is a local kernel use-after-free with high CVSS impact and confirmed exploitation in CISA KEV, though it requires local low-privilege access rather than being remotely reachable.

What it is

A flaw in the Linux kernel nftables subsystem allows an nft object or expression to reference an nft set belonging to a different nft table. When that table is deleted, the dangling reference causes a use-after-free. This matters because it is a memory-corruption bug in a core kernel subsystem that is reachable by a local user with the ability to configure nftables.

Impact

An attacker who can trigger the dangling reference gains use-after-free access in kernel memory, which can lead to privilege escalation or code execution in kernel context, with high impact to confidentiality, integrity and availability.

Attack surface

The CVSS vector is local (AV:L), low complexity, low privileges required, and no user interaction, so it is reached by a local user who can create and delete nftables tables and sets. No remote or network vector is described.

Exploitation

CVE-2022-2586 is listed in CISA KEV with a due date of 2024-07-17, indicating known exploitation, and EPSS gives a 30-day probability of about 10.5 percent (95.5th percentile). CISA records no known ransomware campaign use.

What to do

  • Apply the vendor kernel updates referenced in the Ubuntu security notices (USN-5557-1, USN-5560-1/2, USN-5562-1, USN-5564-1 through USN-5567-1, USN-5582-1) or the equivalent patched kernel for your distribution.
  • If patching is not possible, restrict local access to nftables configuration to trusted users and remove unnecessary local accounts.
  • Follow CISA KEV guidance: apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
  • Track the upstream netfilter-devel patch thread for the fix and confirm your kernel build includes it.
  • Audit systems where unprivileged or low-privilege local users can run nft commands.

Detection

  • Monitor for local processes invoking nft to create sets in one table and delete the owning table shortly after, which is the trigger pattern for the dangling reference.
  • Watch kernel logs for use-after-free, KASAN or slab corruption reports involving nftables or netfilter code paths.
  • Alert on unexpected privilege escalation or suspicious kernel-level activity on hosts where nftables is configured by non-root or low-privilege users.
  • Inventory kernel versions against the patched builds named in the Ubuntu security notices to find unpatched hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-2586 to the Known Exploited Vulnerabilities catalog on 26 June 2024 as "Linux Kernel Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 17 July 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2586 Third Party Advisory
https://lore.kernel.org/netfilter-devel/[email protected]/T/#t Mailing ListPatch
https://ubuntu.com/security/notices/USN-5557-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5560-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5560-2 Third Party Advisory
https://ubuntu.com/security/notices/USN-5562-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5564-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5565-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5566-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5567-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5582-1 Third Party Advisory
https://www.openwall.com/lists/oss-security/2022/08/09/5 Mailing List
https://www.zerodayinitiative.com/advisories/ZDI-22-1118/ Third Party AdvisoryVDB Entry
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2586 Third Party Advisory
https://lore.kernel.org/netfilter-devel/[email protected]/T/#t Mailing ListPatch
https://ubuntu.com/security/notices/USN-5557-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5560-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5560-2 Third Party Advisory
https://ubuntu.com/security/notices/USN-5562-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5564-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5565-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5566-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5567-1 Third Party Advisory
https://ubuntu.com/security/notices/USN-5582-1 Third Party Advisory
https://www.openwall.com/lists/oss-security/2022/08/09/5 Mailing List
https://www.vicarius.io/vsociety/posts/use-after-free-vulnerability-linked-chain-between-nft-tables-cve-2022-2586 ExploitThird Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-22-1118/ Third Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-2586 US Government Resource

Track CVE-2022-2586 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2019-16928Exim heap buffer overflow in string_vformat via long EHLO commandExim 4.92 through 4.92.2 contains a heap-based buffer overflow in string_vformat in string.c triggered by a long EHLO command, allowing remote code e…KEVEPSS 42%analysed9.8CVE-2019-10149Exim MTA improper recipient validation leads to remote command executionExim versions 4.87 through 4.91 fail to properly validate recipient addresses in the deliver_message() function in /src/deliver.c, allowing command i…KEVEPSS 100%analysed9.8CVE-2018-6789Exim SMTP base64d buffer overflow allows remote code executionExim before 4.90.1 contains a buffer overflow in the base64d function of its SMTP listener. A handcrafted message can trigger the overflow, and the f…KEVEPSS 82%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed

Source: NIST National Vulnerability Database (record CVE-2022-2586), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.