Back

HIGH

kernel: a use-after-free write in the netfilter subsystem can lead to privilege escalation to root

Published Jun 2, 2022

Description

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

Affected products

Remediation

Red Hat statement

The latest kernel in RHCOS is kernel-4.18.0-305.49.1.el8 which does not contain the vulnerable code and is not affected, also OCP v4.9 or earlier are not affected.

Red Hat mitigation

In order to trigger the issue, it requires the ability to create user/net namespaces. On non-containerized deployments of Red Hat Enterprise Linux 8, you can disable user namespaces by setting user.max_user_namespaces to 0: # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled.

Weaknesses (1)

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 2, 2022
Updated Aug 3, 2024
Reserved Jun 2, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 31, 2022
ENISA EUVD
Assigner mitre
Published Jun 2, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-53447