{"id":"CVE-2022-2586","title":"It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.","summary":"It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H","cwe":["CWE-416","CWE-416"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 3.16, < 4.14.316","linux_kernel >= 4.15, < 4.19.256","linux_kernel >= 4.20, < 5.4.211","linux_kernel >= 5.5, < 5.10.137","linux_kernel >= 5.11, < 5.15.61","linux_kernel >= 5.16, < 5.18.18","linux_kernel >= 5.19, < 5.19.2","ubuntu_linux = 14.04","ubuntu_linux = 16.04","ubuntu_linux = 18.04","ubuntu_linux = 20.04","ubuntu_linux = 22.04"],"patched":["linux_kernel 5.19.2"],"published":"2024-01-08","updated":"2026-08-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-2586","references":[{"url":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2586","label":"security@ubuntu.com"},{"url":"https://lore.kernel.org/netfilter-devel/20220809170148.164591-1-cascardo@canonical.com/T/#t","label":"security@ubuntu.com"},{"url":"https://ubuntu.com/security/notices/USN-5557-1","label":"security@ubuntu.com"},{"url":"https://ubuntu.com/security/notices/USN-5560-1","label":"security@ubuntu.com"},{"url":"https://ubuntu.com/security/notices/USN-5560-2","label":"security@ubuntu.com"},{"url":"https://ubuntu.com/security/notices/USN-5562-1","label":"security@ubuntu.com"},{"url":"https://ubuntu.com/security/notices/USN-5564-1","label":"security@ubuntu.com"},{"url":"https://ubuntu.com/security/notices/USN-5565-1","label":"security@ubuntu.com"},{"url":"https://ubuntu.com/security/notices/USN-5566-1","label":"security@ubuntu.com"},{"url":"https://ubuntu.com/security/notices/USN-5567-1","label":"security@ubuntu.com"},{"url":"https://ubuntu.com/security/notices/USN-5582-1","label":"security@ubuntu.com"},{"url":"https://www.openwall.com/lists/oss-security/2022/08/09/5","label":"security@ubuntu.com"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-22-1118/","label":"security@ubuntu.com"},{"url":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2586","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lore.kernel.org/netfilter-devel/20220809170148.164591-1-cascardo@canonical.com/T/#t","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ubuntu.com/security/notices/USN-5557-1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ubuntu.com/security/notices/USN-5560-1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ubuntu.com/security/notices/USN-5560-2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ubuntu.com/security/notices/USN-5562-1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ubuntu.com/security/notices/USN-5564-1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ubuntu.com/security/notices/USN-5565-1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ubuntu.com/security/notices/USN-5566-1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ubuntu.com/security/notices/USN-5567-1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ubuntu.com/security/notices/USN-5582-1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.openwall.com/lists/oss-security/2022/08/09/5","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.vicarius.io/vsociety/posts/use-after-free-vulnerability-linked-chain-between-nft-tables-cve-2022-2586","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-22-1118/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-2586","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.10458,"epssPercentile":0.95603,"kev":true,"kevDateAdded":"2024-06-26","kevDueDate":"2024-07-17","kevRansomware":false,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-13T20:06:15.105Z","exploits":{"github":3,"githubRepos":["https://github.com/aels/CVE-2022-2586-LPE","https://github.com/sniper404ghostxploit/CVE-2022-2586","https://github.com/lanleft/CVE-2022-2586"],"checkedAt":"2026-09-21T15:26:08.919Z"},"exploitAvailable":true,"slug":"CVE-2022-2586","body":"## Overview\n\nIt was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.\n\n## Affected\n\n- `linux_kernel >= 3.16, < 4.14.316`\n- `linux_kernel >= 4.15, < 4.19.256`\n- `linux_kernel >= 4.20, < 5.4.211`\n- `linux_kernel >= 5.5, < 5.10.137`\n- `linux_kernel >= 5.11, < 5.15.61`\n- `linux_kernel >= 5.16, < 5.18.18`\n- `linux_kernel >= 5.19, < 5.19.2`\n- `ubuntu_linux = 14.04`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `ubuntu_linux = 20.04`\n- `ubuntu_linux = 22.04`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.19.2`","depth":"midnight","depthScore":56,"depthScoreParts":{"impact":29.2,"likelihood":2.1,"exploitation":25,"ransomware":0},"changes":[{"seq":4677,"id":"CVE-2022-2586","ts":1788887199004,"field":"exploit_available","old":"false","new":"true"},{"seq":3560,"id":"CVE-2022-2586","ts":1788886315429,"field":"exploit_available","old":"true","new":"false"},{"seq":2414,"id":"CVE-2022-2586","ts":1788882984267,"field":"exploit_available","old":"false","new":"true"},{"seq":1443,"id":"CVE-2022-2586","ts":1788882397447,"field":"exploit_available","old":"true","new":"false"},{"seq":557,"id":"CVE-2022-2586","ts":1788881833779,"field":"exploit_available","old":"false","new":"true"}]}