kernel: a use-after-free write in the netfilter subsystem can lead to privilege escalation to root
Published Jun 2, 2022
7.8
HIGHCVSS 3.1
EPSS 2.91%
Description
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
Affected products
No data.
Configuration 1
- ≥ 4.1 · < 4.9.318
- ≥ 4.10 · < 4.14.283
- ≥ 4.15 · < 4.19.247
- ≥ 4.20 · < 5.4.198
- ≥ 5.5 · < 5.10.120
- ≥ 5.11 · < 5.15.45
- ≥ 5.16 · < 5.17.13
- ≥ 5.18 · < 5.18.2
Configuration 2
- 35
- 36
Configuration 3
- 9.0
- 10.0
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1160.71.1.el7
Fixed · RHSA-2022:5232
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1160.71.1.rt56.1212.el7
Fixed · RHSA-2022:5236
Red Hat Enterprise Linux 7
kpatch-patch
Fixed · RHSA-2022:5216
Red Hat Enterprise Linux 7.3 Advanced Update Support
kernel-0:3.10.0-514.104.1.el7
Fixed · RHSA-2022:5806
Red Hat Enterprise Linux 7.4 Advanced Update Support
kernel-0:3.10.0-693.104.1.el7
Fixed · RHSA-2022:5805
Red Hat Enterprise Linux 7.6 Advanced Update Support
kernel-0:3.10.0-957.95.1.el7
Fixed · RHSA-2022:5802
Red Hat Enterprise Linux 7.6 Telco Extended Update Support
kernel-0:3.10.0-957.95.1.el7
Fixed · RHSA-2022:5802
Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions
kernel-0:3.10.0-957.95.1.el7
Fixed · RHSA-2022:5802
Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2022:5804
Red Hat Enterprise Linux 7.7 Advanced Update Support
kernel-0:3.10.0-1062.68.1.el7
Fixed · RHSA-2022:6073
Red Hat Enterprise Linux 7.7 Telco Extended Update Support
kernel-0:3.10.0-1062.68.1.el7
Fixed · RHSA-2022:6073
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
kernel-0:3.10.0-1062.68.1.el7
Fixed · RHSA-2022:6073
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2022:6075
Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.19.1.el8_6
Fixed · RHSA-2022:5819
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-372.19.1.rt7.176.el8_6
Fixed · RHSA-2022:5834
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2022:5839
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
kernel-0:4.18.0-147.70.1.el8_1
Fixed · RHSA-2022:5636
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2022:5648
Red Hat Enterprise Linux 8.2 Extended Update Support
kernel-0:4.18.0-193.87.1.el8_2
Fixed · RHSA-2022:5220
Red Hat Enterprise Linux 8.2 Extended Update Support
kernel-rt-0:4.18.0-193.87.1.rt13.137.el8_2
Fixed · RHSA-2022:5224
Red Hat Enterprise Linux 8.2 Extended Update Support
kpatch-patch
Fixed · RHSA-2022:5476
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-0:4.18.0-305.57.1.el8_4
Fixed · RHSA-2022:5626
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-rt-0:4.18.0-305.57.1.rt7.129.el8_4
Fixed · RHSA-2022:5633
Red Hat Enterprise Linux 8.4 Extended Update Support
kpatch-patch
Fixed · RHSA-2022:5641
Red Hat Enterprise Linux 9
kernel-0:5.14.0-70.17.1.el9_0
Fixed · RHSA-2022:5249
Red Hat Enterprise Linux 9
kernel-0:5.14.0-70.17.1.el9_0
Fixed · RHSA-2022:5249
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-70.17.1.rt21.89.el9_0
Fixed · RHSA-2022:5267
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2022:5214
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.23-20220622.0.el7_9
Fixed · RHSA-2022:5439
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.19.1.el8_6
Fixed · RHSA-2022:5819
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.5.2-202209140405_8.6
Fixed · RHSA-2022:6551
Red Hat Enterprise Linux 6
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1160.71.1.el7 | Fixed | RHSA-2022:5232 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1160.71.1.rt56.1212.el7 | Fixed | RHSA-2022:5236 |
| Red Hat Enterprise Linux 7 | kpatch-patch | Fixed | RHSA-2022:5216 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | kernel-0:3.10.0-514.104.1.el7 | Fixed | RHSA-2022:5806 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | kernel-0:3.10.0-693.104.1.el7 | Fixed | RHSA-2022:5805 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | kernel-0:3.10.0-957.95.1.el7 | Fixed | RHSA-2022:5802 |
| Red Hat Enterprise Linux 7.6 Telco Extended Update Support | kernel-0:3.10.0-957.95.1.el7 | Fixed | RHSA-2022:5802 |
| Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions | kernel-0:3.10.0-957.95.1.el7 | Fixed | RHSA-2022:5802 |
| Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2022:5804 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | kernel-0:3.10.0-1062.68.1.el7 | Fixed | RHSA-2022:6073 |
| Red Hat Enterprise Linux 7.7 Telco Extended Update Support | kernel-0:3.10.0-1062.68.1.el7 | Fixed | RHSA-2022:6073 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | kernel-0:3.10.0-1062.68.1.el7 | Fixed | RHSA-2022:6073 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2022:6075 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.19.1.el8_6 | Fixed | RHSA-2022:5819 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-372.19.1.rt7.176.el8_6 | Fixed | RHSA-2022:5834 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2022:5839 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | kernel-0:4.18.0-147.70.1.el8_1 | Fixed | RHSA-2022:5636 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2022:5648 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | kernel-0:4.18.0-193.87.1.el8_2 | Fixed | RHSA-2022:5220 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | kernel-rt-0:4.18.0-193.87.1.rt13.137.el8_2 | Fixed | RHSA-2022:5224 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | kpatch-patch | Fixed | RHSA-2022:5476 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-0:4.18.0-305.57.1.el8_4 | Fixed | RHSA-2022:5626 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-rt-0:4.18.0-305.57.1.rt7.129.el8_4 | Fixed | RHSA-2022:5633 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kpatch-patch | Fixed | RHSA-2022:5641 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-70.17.1.el9_0 | Fixed | RHSA-2022:5249 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-70.17.1.el9_0 | Fixed | RHSA-2022:5249 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-70.17.1.rt21.89.el9_0 | Fixed | RHSA-2022:5267 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2022:5214 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.23-20220622.0.el7_9 | Fixed | RHSA-2022:5439 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.19.1.el8_6 | Fixed | RHSA-2022:5819 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.5.2-202209140405_8.6 | Fixed | RHSA-2022:6551 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The latest kernel in RHCOS is kernel-4.18.0-305.49.1.el8 which does not contain the vulnerable code and is not affected, also OCP v4.9 or earlier are not affected.
Red Hat mitigation
In order to trigger the issue, it requires the ability to create user/net namespaces. On non-containerized deployments of Red Hat Enterprise Linux 8, you can disable user namespaces by setting user.max_user_namespaces to 0: # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled.
References (22)
- http://www.openwall.com/lists/oss-security/2022/06/03/1 mailing-listx_refsource_MLISTExploitMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/06/04/1 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/06/20/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/07/03/5 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/07/03/6 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/08/25/1 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/09/02/9 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-32250 Vendor Advisory
- https://blog.theori.io/research/CVE-2022-32250-linux-kernel-lpe-2022/ x_refsource_MISCExploitThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2092427 x_refsource_MISCIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53447 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/net/netfilter?id=520778042ccca019f3ffa136dd0ca565c486cedd x_refsource_MISCMailing ListPatchVendor Advisory
- https://github.com/theori-io/CVE-2022-32250-exploit x_refsource_MISCExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MO6Y3TC4WUUNKRP7OQA26OVTZTPCS6F2/ x_refsource_MISC
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UIZTJOJCVVEJVOQSCHE6IJQKMPISHQ5L/ x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2022-32250
- https://security.netapp.com/advisory/ntap-20220715-0005/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-32250
- https://www.debian.org/security/2022/dsa-5161 x_refsource_MISCThird Party Advisory
- https://www.debian.org/security/2022/dsa-5173 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.openwall.com/lists/oss-security/2022/05/31/1 x_refsource_MISCExploitMailing ListPatchThird Party Advisory
Change history (0)
No recorded changes yet.