CVE-2022-34918 Details
Description
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.1, < 4.14.316 >= 4.15, < 4.19.284 >= 4.20, < 5.4.244 >= 5.5, < 5.10.130 >= 5.11, < 5.15.54 >= 5.16, < 5.18.11 |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
| canonical ubuntu linux | 14.04 16.04 18.04 20.04 22.04 |
CPE
Remediation
| |
| netapp h300s firmware | All versions |
CPE
Remediation
| |
| netapp h300s | All versions |
CPE
Remediation
| |
| netapp h500s firmware | All versions |
CPE
Remediation
| |
| netapp h500s | All versions |
CPE
Remediation
| |
| netapp h700s firmware | All versions |
CPE
Remediation
| |
| netapp h700s | All versions |
CPE
Remediation
| |
| netapp h410s firmware | All versions |
CPE
Remediation
| |
| netapp h410s | All versions |
CPE
Remediation
| |
| netapp h410c firmware | All versions |
CPE
Remediation
| |
| netapp h410c | All versions |
CPE
Remediation
| |
Change History
15 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Sep 12, 2023 | Reanalysis | [email protected] |
| May 16, 2023 | Reanalysis | [email protected] |
| Oct 26, 2022 | Modified Analysis | [email protected] |
| Sep 28, 2022 | CVE Modified | [email protected] |
| Aug 30, 2022 | CVE Modified | [email protected] |
| Aug 26, 2022 | CVE Modified | [email protected] |
| Aug 6, 2022 | CVE Modified | [email protected] |
| Jul 27, 2022 | CVE Modified | [email protected] |
| Jul 21, 2022 | CVE Modified | [email protected] |
| Jul 13, 2022 | Initial Analysis | [email protected] |
| Jul 5, 2022 | CVE Modified | [email protected] |