A use-after-free write flaw in the Linux kernel's Netfilter nf_tables/nftables subsystem, tracked as CVE-2022-32250, can allow a local attacker to escalate privileges to root. The defect is triggered by supplying a non-stateful lookup or dynset expression as a subexpression in an NFT_MSG_NEWSET operation: the expression is bound to a set, then freed without removal from the set's binding list, leaving a stale reference that can be used for memory corruption.
Researchers demonstrated exploitation on Ubuntu 22.04 running kernel 5.15.0-27-generic, using user_key_payload and POSIX message queues to leak heap and KASLR addresses before overwriting modprobe_path for root execution. Exploitation requires the ability to create user and network namespaces. The upstream fix, committed as 520778042ccca019f3ffa136dd0ca565c486cedd, moves NFT_EXPR_STATEFUL validation into nft_expr_init so unsupported expressions are rejected before allocation and binding can create the dangling reference.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A technical write-up demonstrated exploitation on Ubuntu 22.04 with kernel 5.15.0-27-generic, using heap and KASLR leaks followed by a controlled write to overwrite modprobe_path. The write-up stated that full exploit code was published in a GitHub repository for educational and research purposes.
The Linux kernel netdev tree fixed the issue in commit 520778042ccca019f3ffa136dd0ca565c486cedd. The fix prevents unsupported non-stateful expressions from being allocated and bound as set subexpressions.
EDG reported CVE-2022-32250, a use-after-free write flaw in the Linux Netfilter nf_tables subsystem that can enable local privilege escalation to root. The flaw leaves a stale set binding when non-stateful lookup or dynset expressions are rejected during NFT_MSG_NEWSET processing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
theori.io
Open sourcegit.kernel.org
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.