CVE-2022-25636
HIGH 7.8EPSS 2.6%
net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 2.63% chance of exploitation in the next 30 days, 84th percentile
- Published
- 2022-02-22
- Updated
- 2024-08-03
Proof-of-concept exploits (4)
- Bonfee/CVE-2022-25636437★ · 2022-03-07
- https://nickgregory.me/linux/security/2022/03/12/cve-2022-25636/
- chenaotian/CVE-2022-256363★ · 2022-03-24
- veritas501/CVE-2022-25636-PipeVersion19★ · 2022-04-05