FlawAtlas
Search the atlas
CVE-2022-2586 Moderate

Confirmed as exploited

CVE-2022-2586

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

Exploit probability 10.5%
Published January 8, 2024
Required by July 17, 2024
Last source change August 15, 2026

01 / ACTION

Required action

Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

736 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2022-2586

Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges.

View original source
Open Source Vulnerabilities CVE-2022-2586

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

View original source

05 / REFERENCES

Further evidence