CVE-2022-25636 is a heap out-of-bounds write in the Linux kernel Netfilter subsystem. The flaw occurs in nft_fwd_dup_netdev_offload in net/netfilter/nf_dup_netdev.c and is related to nf_tables_offload. Linux kernel versions 5.4 through 5.6.10 are affected. A local user can access out-of-bounds memory through the vulnerable code path.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a local privilege escalation exploit for CVE-2022-25636, a vulnerability in the Linux kernel's nftables subsystem. The main exploit logic is implemented in 'exploit.c', which is a large C file that orchestrates the attack. The exploit leverages a 'pipe-primitive' technique to avoid the need for KASLR, SMAP, SMEP, or KPTI bypasses. The attack involves heap spraying, message queue manipulation, and use-after-free (UAF) primitives to gain arbitrary write capabilities in kernel memory. The exploit's end goal is to overwrite '/usr/bin/mount' with a statically embedded SUID shell binary, which is then executed to obtain root privileges. The repository also includes a set of header files under 'include/libmnl/' and 'include/libnftnl/' that provide userland interfaces to netlink and nftables, which are used by the exploit. The Makefile provides a static compilation recipe for the exploit. The exploit is operational and weaponized for local privilege escalation on vulnerable Linux systems. No network endpoints are involved; the attack is purely local and targets the file '/usr/bin/mount'.
This repository contains a local privilege escalation exploit for CVE-2022-25636, a vulnerability in the Linux kernel's nftables subsystem. The exploit is implemented in C and consists of several files: 'exploit.c' (main exploit logic), 'fakefuse.c' and 'fakefuse.h' (implementing a fake FUSE filesystem for heap spraying and synchronization), and 'util.c'/'util.h' (helper functions for message queues). The Makefile builds the exploit binary from these sources. The exploit works by creating and manipulating nftables tables and chains, performing heap spraying using FUSE and setxattr, leaking kernel addresses to bypass KASLR, and finally constructing a ROP chain to escalate privileges to root. The exploit targets the loopback device ('lo') and uses the mount point '/tmp/foo' for the FUSE filesystem. The README notes that the exploit is unstable (about 40% success rate) and may cause kernel panics or heap corruption on failure. The exploit is operational and provides a root shell if successful.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel heap out-of-bounds write vulnerability in nf_dup_netdev.c affecting the Rocky Linux 8 kernel packages referenced by CIQ advisory crlsa-2022_1555.
A Linux kernel heap out-of-bounds write vulnerability in nf_dup_netdev.c. Red Hat fixed it in its kernel-rt update for RHEL 8.4.
A Linux kernel heap out-of-bounds write vulnerability in nf_dup_netdev.c.
A Linux kernel heap out-of-bounds write vulnerability in nf_dup_netdev.c.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.