HIGH

CVE-2022-34918

CVSS v3

7.8

HIGH

EPSS Score

40.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.

Technical details

Published
7/4/2022

Frequently asked questions

What is CVE-2022-34918?

An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.

Is CVE-2022-34918 actively exploited?

Active exploitation of CVE-2022-34918 has not been confirmed. The EPSS score is 40.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-34918?

CVE-2022-34918 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2022-34918 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.