← לוח פגיעויות

CVE-2022-2586

גבוהה 7.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Linux Kernel Use-After-Free Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

תיאור (מקור, אנגלית)

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

מדדים

CVSS 3.1
7.8 (HIGH) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
10% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-416

מוצרים מושפעים

linux: linux kernel; canonical: ubuntu linux

קישורים