CVE-2022-32250

HIGH

Linux Kernel < 4.9.318 - Use After Free

Title source: rule

Description

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

Exploits (10)

nomisec WORKING POC 177 stars
by theori-io · poc
https://github.com/theori-io/CVE-2022-32250-exploit
nomisec WORKING POC 9 stars
by ysanatomic · poc
https://github.com/ysanatomic/CVE-2022-32250-LPE
nomisec WORKING POC 3 stars
by seadragnol · poc
https://github.com/seadragnol/CVE-2022-32250
nomisec WORKING POC 2 stars
by g3un · poc
https://github.com/g3un/cve-2022-32250
nomisec WORKING POC 1 stars
by LSinus · poc
https://github.com/LSinus/CacheMeIfYouCan
nomisec WORKING POC 1 stars
by Kristal-g · poc
https://github.com/Kristal-g/CVE-2022-32250
nomisec NO CODE 1 stars
by Decstor5 · poc
https://github.com/Decstor5/2022-32250LPE
nomisec NO CODE
by Noidolosity · poc
https://github.com/Noidolosity/CVE-2022-32250
nomisec NO CODE
by rem0t3 · poc
https://github.com/rem0t3/CVE-2022-32250-Compiled
nomisec WRITEUP
by KuanKuanQAQ · poc
https://github.com/KuanKuanQAQ/cve-testing

References (18)

Scores

CVSS v3 7.8
EPSS 0.0188
EPSS Percentile 83.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (10)
debian/debian_linux 9.0
debian/debian_linux 10.0
fedoraproject/fedora 35
fedoraproject/fedora 36
linux/linux_kernel 4.1 - 4.9.318
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h700s_firmware
Published Jun 02, 2022
Tracked Since Feb 18, 2026