CVE-2022-32250: Use After Free
A use-after-free vulnerability was found in the Linux kernel's Netfilter subsystem in net/netfilter/nftablesapi.c. This flaw allows a local attacker with user access to cause a privilege escalation issue.
Other sources
A use-after-free write vulnerability was identified within the netfilter subsystem which can be exploited to achieve privilege escalation to root. In order to trigger the issue it requires the ability to create user/net namespaces.
Reference:
https://www.openwall.com/lists/oss-security/2022/05/31/1
— Red Hat
net/netfilter/nftablesapi.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFTSTATEFULEXPR check leads to a use-after-free.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.71.1.rt56.1212.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.71.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-514.104.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-693.104.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.95.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.68.1.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-372.19.1.rt7.176.el8_6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-372.19.1.el8_6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-147.70.1.el8_1 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.87.1.rt13.137.el8_2 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.87.1.el8_2 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.57.1.rt7.129.el8_4 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.57.1.el8_4 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:5.14.0-70.17.1.el9_0 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:5.14.0-70.17.1.rt21.89.el9_0 - Upgrade
Upgrade
redhat/redhat-virtualization-hostto a version that resolves this vulnerability.Fixed in 0:4.3.23-20220622.0.el7_9 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 4.19.249-2Fixed in 4.19.289-2Fixed in 5.10.197-1Fixed in 5.10.205-2Fixed in 6.1.66-1Fixed in 6.1.69-1Fixed in 6.5.13-1Fixed in 6.6.9-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.4.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.6.0 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.19 - Configuration
On non-containerized deployments of Red Hat Enterprise Linux 8, disable user namespaces by setting user.max_user_namespaces to 0 (e.g., write "user.max_user_namespaces=0" to /etc/sysctl.d/userns.conf and apply with sysctl -p /etc/sysctl.d/userns.conf). Do not apply this mitigation on containerized deployments (e.g., Red Hat OpenShift Container Platform) where user namespaces must remain enabled.
Linux kernel (sysctl) user.max_user_namespaces = 0
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2022:5236
- RHSA-2022:5216
- RHSA-2022:5232
- RHSA-2022:5806
- RHSA-2022:5805
- RHSA-2022:5802
- RHSA-2022:5804
- RHSA-2022:6073
- RHSA-2022:6075
- RHSA-2022:5834
- RHSA-2022:5819
- RHSA-2022:5839
- RHSA-2022:5636
- RHSA-2022:5648
- RHSA-2022:5224
- RHSA-2022:5220
- RHSA-2022:5476
- RHSA-2022:5633
- RHSA-2022:5626
- RHSA-2022:5641
- RHSA-2022:5249
- RHSA-2022:5267
- RHSA-2022:5214
- RHSA-2022:5439
- RHSA-2022:6551