CVE-2022-1016

medium
Published 2022-11-15 · Modified 2022-11-18
CVSS v3
VIR risk
5.5

Description

A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
arch archfixed5.17.5.hardened1-1
almalinux almalinux9fixedkernel-rt-debug-core-5.14.0-162.6.1.rt21.168.el9_1.x86_64.rpm
redhat rhel9fixed
rockylinux rocky8fixed
suse slesaffected
debian debianbookwormfixed5.16.18-1
debian debianbullseyefixed5.10.113-1
debian debianforkyfixed5.16.18-1
debian debiansidfixed5.16.18-1
debian debiantrixiefixed5.16.18-1

References

💬 Discuss CVE-2022-1016 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.