CVE-2022-2586

Updated: 2025-11-03 03:02:51.610635

Description:

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Known exploits

Added Date Description Due Date Notes
2024-06-26 Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges. 2024-07-17 This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://seclists.org/oss-sec/2022/q3/131; https://nvd.nist.gov/vuln/detail/CVE-2022-2586

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Already Fixed 2024-01-20 08:36:52
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2024-07-01 10:15:25
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Already Fixed 2024-07-01 10:15:25
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1705927008 2024-01-22 08:40:43
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1705927642 2024-01-22 08:40:44
CentOS Stream 8 ELS kernel 4.18.0 7.8 HIGH Already Fixed 2024-06-29 10:07:50
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2024-07-01 10:15:25
CloudLinux 7 ELS kernel 3.10.0 7.8 HIGH Ignored 2025-11-08 02:29:13 CL7 support is limited
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2024-09-01 12:26:58
Oracle Linux 7 ELS kernel 3.10.0 7.8 HIGH Already Fixed 2025-05-11 04:36:23
Total: 17