Executive brief
A use-after-free vulnerability in the Linux Kernel's netfilter (nft_object) occurs when an object or expression references a set on a different table. When that table is deleted, the reference remains, allowing local attackers to escalate privileges.
Affected products
- Linux Linux Kernel up to (including) 5.19.17, 6.0
- Canonical Ubuntu Linux 14.04 ESM, 16.04 ESM, 18.04 ESM, 20.04 LTS
Timeline
- 2022-08-09: disclosed: Public disclosure via oss-security mailing list.
- 2024-06-26: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2024-07-17: other: CISA due date for remediation.