Back

MEDIUM

kernel: arbitrary code execution in linux/net/netfilter/nf_tables_api.c

Published Apr 29, 2022

Description

A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue.

Affected products

Remediation

Red Hat statement

There was no shipped kernel version that was seen affected by this problem.

Red Hat mitigation

In order to trigger the issue, it requires the ability to create user/net namespaces. On non-containerized deployments of Red Hat Enterprise Linux 8, you can disable user namespaces by setting user.max_user_namespaces to 0: # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 29, 2022
Updated Aug 2, 2024
Reserved Mar 17, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 28, 2022