FlawAtlas
Search the atlas
USN-5557-1 Not scored

linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities

Zhenpeng Lin discovered that the network packet scheduler implementation in the Linux kernel did not properly remove all references to a route filter before freeing it in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-2588) It was discovered that the netfilter subsystem of the Linux kernel did not prevent one nft object from referencing an nft set in another nft table, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-2586)

Exploit probability Not scored
Published August 9, 2022
Required by Not available
Last source change June 29, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:Pro:14.04:LTS linux-aws

76 explicit affected versions

Ubuntu:Pro:14.04:LTS linux-lts-xenial

120 explicit affected versions

Ubuntu:Pro:16.04:LTS linux

143 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-aws

98 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-kvm

77 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-5557-1

Zhenpeng Lin discovered that the network packet scheduler implementation in the Linux kernel did not properly remove all references to a route filter before freeing it in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-2588) It was discovered that the netfilter subsystem of the Linux kernel did not prevent one nft object from referencing an nft set in another nft table, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-2586)

View original source

05 / REFERENCES

Further evidence