CVE-2022-34918

HIGH EXPLOITED

Netfilter nft_set_elem_init Heap Overflow Privilege Escalation

Title source: metasploit

Description

An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.

Exploits (6)

nomisec WORKING POC 245 stars
by randorisec · local
https://github.com/randorisec/CVE-2022-34918-LPE-PoC
nomisec WORKING POC 219 stars
by veritas501 · local
https://github.com/veritas501/CVE-2022-34918
nomisec WORKING POC 2 stars
by merlinepedra · poc
https://github.com/merlinepedra/CVE-2022-34918-LPE-PoC
nomisec WORKING POC 2 stars
by merlinepedra25 · poc
https://github.com/merlinepedra25/CVE-2022-34918-LPE-PoC
nomisec WORKING POC
by linulinu · poc
https://github.com/linulinu/CVE-2022-34918
metasploit WORKING POC NORMAL
rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/netfilter_nft_set_elem_init_privesc.rb

Scores

CVSS v3 7.8
EPSS 0.3234
EPSS Percentile 96.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-02-26
CWE
CWE-843
Status published
Products (12)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 20.04
canonical/ubuntu_linux 22.04
debian/debian_linux 11.0
linux/linux_kernel 4.1 - 4.14.316
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
... and 2 more
Published Jul 04, 2022
Tracked Since Feb 18, 2026