CVE-2022-1015 is an out-of-bounds write vulnerability in the Linux kernel's netfilter subsystem, specifically in linux/net/netfilter/nf_tables_api.c. A local user can exploit this flaw to write outside the bounds of allocated memory, potentially leading to privilege escalation or arbitrary code execution within the kernel context. This vulnerability is one of several affecting Siemens SIPLUS TIM 1531 IRC industrial control devices prior to version 2.4.8, which integrate affected Linux kernel versions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) local privilege escalation exploit for CVE-2022-1015, an out-of-bounds read/write vulnerability in the Linux kernel's nf_tables subsystem. The repository consists of three files: a detailed write-up (writeup.md), a README with build and usage instructions, and the main exploit code (exploit.c). The exploit is written in C and leverages the nf_tables API via libmnl and libnftnl to create custom tables and chains, then injects crafted rules to leak kernel addresses and execute a ROP chain for privilege escalation. The exploit operates in two stages: first, it leaks the kernel base address using UDP packets sent to 127.0.0.1 on port 50005; second, it triggers the ROP chain using TCP packets on port 50006, ultimately granting root privileges to the attacker. The exploit is a PoC and requires adaptation for different kernel builds due to varying offsets and ROP gadgets. No remote or network attack vector is present; the exploit must be run locally on a vulnerable system.
This repository is a proof-of-concept (PoC) exploit for CVE-2022-1015, a local privilege escalation vulnerability in the Linux kernel's nf_tables component. The exploit is implemented in C and consists of three main code files: 'pwn.c' (main exploit logic), 'helpers.c', and 'helpers.h' (utility functions for interacting with nftables and networking). The Makefile is provided for building the exploit, which requires libmnl, libnftnl, and appropriate Linux kernel headers. The exploit works by creating and manipulating nftables tables, chains, and rules to leak kernel addresses via UDP packets and then installing a kernel ROP chain to escalate privileges. The exploit is highly unstable and may cause kernel panics; it is intended for research and demonstration purposes. The README provides detailed build instructions, affected kernel versions, and caveats regarding exploit reliability. No remote or network attack vector is present; the exploit must be run locally on a vulnerable system.
This repository contains a local privilege escalation exploit for CVE-2022-1015, a vulnerability in the Linux kernel's nftables subsystem. The exploit is implemented in C (main file: ex.c) and leverages out-of-bounds (OOB) read/write in the kernel stack via crafted nftables rules. The exploit works in two stages: first, it leaks the kernel base address by installing specific nftables rules and sending/receiving UDP packets on localhost (127.0.0.1, port 31337). Then, it installs a second set of rules and sends a ROP chain payload to escalate privileges by calling commit_creds(init_cred), ultimately spawning a root shell. The exploit requires the ability to create new user and network namespaces and interacts with several /proc files to set up the required environment. The repository includes a Makefile for building the exploit, a README.md with technical details and kernel code references, ex.c (the main exploit logic), and utils.h (helper functions for namespace and nftables manipulation).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.