kernel: uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM
Published Aug 29, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.43%
Description
A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version Affects v3.13-rc1 and later, Fixed in v5.18-rc1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
Configuration 1
- ≤ 3.12
- ≥ 3.13 · ≤ 5.17
- 3.13
Configuration 2
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-425.3.1.el8
Fixed · RHSA-2022:7683
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-425.3.1.rt7.213.el8
Fixed · RHSA-2022:7444
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.6.1.el9_1
Fixed · RHSA-2022:8267
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.6.1.el9_1
Fixed · RHSA-2022:8267
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-162.6.1.rt21.168.el9_1
Fixed · RHSA-2022:7933
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.64.1.el9_0
Fixed · RHSA-2023:4137
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.64.1.rt21.135.el9_0
Fixed · RHSA-2023:4138
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Virtualization 4
redhat-virtualization-host
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-425.3.1.el8 | Fixed | RHSA-2022:7683 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-425.3.1.rt7.213.el8 | Fixed | RHSA-2022:7444 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.6.1.el9_1 | Fixed | RHSA-2022:8267 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.6.1.el9_1 | Fixed | RHSA-2022:8267 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-162.6.1.rt21.168.el9_1 | Fixed | RHSA-2022:7933 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.64.1.el9_0 | Fixed | RHSA-2023:4137 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.64.1.rt21.135.el9_0 | Fixed | RHSA-2023:4138 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
On non-containerized deployments of Red Hat Enterprise Linux, you can disable user namespaces by setting user.max_user_namespaces to 0: # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.43% (0.00434) | 35.39th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.42% (0.00419) | 33.27th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.01% (0.00009) | 0.44th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.06% (0.00058) | 25.95th | v3 (v2023.03.01) |
| May 1, 2024 | 0.04% (0.00045) | 14.27th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00045) | 12.27th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.67% (0.01669) | 76.02th | v2 (v2022.01.01) |
| Feb 13, 2023 | 1.67% (0.01669) | 75.51th | v2 (v2022.01.01) |
| Feb 3, 2023 | 4.41% (0.04411) | 87.78th | v2 (v2022.01.01) |
| Aug 30, 2022 | 1.67% (0.01669) | 75.02th | v2 (v2022.01.01) |
References (6)
- http://blog.dbouman.nl/2022/04/02/How-The-Tables-Have-Turned-CVE-2022-1015-1016/ x_refsource_MISCExploitThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-1016 x_refsource_MISCThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2066614 x_refsource_MISCIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1016
- https://seclists.org/oss-sec/2022/q1/205 x_refsource_MISCExploitMailing ListThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-1016
| Link | Providers | Tags |
|---|---|---|
| http://blog.dbouman.nl/2022/04/02/How-The-Tables-Have-Turned-CVE-2022-1015-1016/ | x_refsource_MISCExploitThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2022-1016 | x_refsource_MISCThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2066614 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1016 | ||
| https://seclists.org/oss-sec/2022/q1/205 | x_refsource_MISCExploitMailing ListThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-1016 |
Change history (0)
No recorded changes yet.