Database/Kernel, userspace & hypervisor
Linux kernel (nf_tables): Heap overflow in nft_set_elem_init() - local root, weaponised inside containers
CVSS 7.8CVE-2022-34918Kernel, userspace & hypervisorcurated
Impact
Heap overflow in nft_set_elem_init() - local root, weaponised inside containers
Who can reach it
Any tenant process in a container with CAP_NET_ADMIN in a userns
What to do
Livepatchable; otherwise drain + reboot
References
Related entries
- Linux kernel (nf_tables): Use-after-free in nft_chain_lookup_byid() - local root (Pwn2Own Vancouver chain)CVE-2023-31248 · Linux kernel (nf_tables)High
- Linux kernel (nf_tables): Use-after-free in nf_tables anonymous-set batch processingCVE-2023-32233 · Linux kernel (nf_tables)High
- Linux kernel (nf_tables): UAF in nft_set_lookup_global after mixed named/anonymous set batches - local rootCVE-2023-3390 · Linux kernel (nf_tables)High
- Linux kernel (nf_tables): Stack out-of-bounds read/write in nft_byteorder_eval() - local root (Pwn2Own)CVE-2023-35001 · Linux kernel (nf_tables)High
- Linux kernel (nf_tables): UAF adding a rule with NFTA_RULE_CHAIN_ID - local rootCVE-2023-4147 · Linux kernel (nf_tables)High
- Linux kernel (nf_tables): Use-after-free in nft_verdict_init() - double-free to local rootCVE-2024-1086 · Linux kernel (nf_tables)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.