CVE-2022-50213

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
18/06/2025
Last modified:
19/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> netfilter: nf_tables: do not allow SET_ID to refer to another table<br /> <br /> When doing lookups for sets on the same batch by using its ID, a set from a<br /> different table can be used.<br /> <br /> Then, when the table is removed, a reference to the set may be kept after<br /> the set is freed, leading to a potential use-after-free.<br /> <br /> When looking for sets by ID, use the table that was used for the lookup by<br /> name, and only return sets belonging to that same table.<br /> <br /> This fixes CVE-2022-2586, also reported as ZDI-CAN-17470.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 3.16 (including) 4.19.256 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.20 (including) 5.4.211 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.137 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.61 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 5.18.18 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.19 (including) 5.19.2 (excluding)