CVE-2022-2586
KEVHIGH 7.8EPSS 10.5%
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H - EPSS
- 10.46% chance of exploitation in the next 30 days, 95th percentile
- CISA KEV
- added 2024-06-26
- Published
- 2024-01-08
- Updated
- 2026-08-20
Proof-of-concept exploits (8)
- https://www.vicarius.io/vsociety/posts/use-after-free-vulnerability-linked-chain-between-…
- Trickhish/automated_privilege_escalation1★ · 2024-01-20
- aels/CVE-2022-2586-LPE21★ · 2022-09-03
- greek0x0/2022-LPE-UAF9★ · 2022-09-01
- konoha279/2022-LPE-UAF5★ · 2022-08-23
- pirenga/2022-LPE-UAF6★ · 2022-08-23
- sniper404ghostxploit/CVE-2022-25862★ · 2022-11-06
- lanleft/CVE-2022-2586