Red Hat remediated CVE-2022-2078, a moderate-severity classic buffer overflow (CWE-120) in the Linux kernel Netfilter/nftables function nft_set_desc_concat_parse(). A low-privileged local attacker could trigger the flaw to cause denial of service and potentially execute code. The vulnerability was fixed upstream in commit fecf31ee395b0295f2d7260aa29946b7605f7c85; CVE-2022-1972 was identified as a duplicate CVE for the same issue.
Affected Red Hat products received updated kernel packages for RHEL 8, RHEL 9, and Red Hat Virtualization 4 on RHEL 8; RHEL 6 and RHEL 7 kernels were not affected. RHSA-2022:6582 delivered the RHEL 9 kernel-rt fix in version 5.14.0-70.26.1.rt21.98.el9_0, alongside remediation for CVE-2022-34918. Organizations should install the applicable kernel updates and reboot systems, as no separate Red Hat-supported mitigation was available.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat fixed affected RHEL 8 kernel-rt packages through RHSA-2022:7444 and kernel packages through RHSA-2022:7683.
Red Hat issued RHSA-2022:6582 for RHEL 9 kernel-rt and RHSA-2022:6610 for the RHEL 9 kernel, addressing CVE-2022-2078. The kernel-rt advisory supplied version 5.14.0-70.26.1.rt21.98.el9_0 and required affected systems to reboot after installation.
Red Hat addressed CVE-2022-2078 for the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 on RHEL 8 through RHSA-2024:0724.
Red Hat closed the Bugzilla issue associated with CVE-2022-2078 and directed subsequent product-status updates to its CVE page.
The upstream Linux kernel project fixed the vulnerability in commit fecf31ee395b0295f2d7260aa29946b7605f7c85, modifying net/netfilter/nf_tables_api.c.
CVE-2022-2078 was identified in the Linux kernel Netfilter/nftables function nft_set_desc_concat_parse(). A low-privileged local attacker could trigger a buffer overflow causing denial of service and potentially unauthorized code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.