CVE Vulnerabilities

CVE-2022-1016

Missing Initialization of Resource

Published: Aug 29, 2022 | Modified: Jun 27, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle return with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker.

Weakness

The product does not initialize a critical resource.

Affected Software

Name Vendor Start Version End Version
Linux_kernel Linux * 3.12 (including)
Linux_kernel Linux 3.13 (including) 5.17 (including)
Linux_kernel Linux 3.13-rc1 (including) 3.13-rc1 (including)

Potential Mitigations

References