← back
CVE-2022-34918observed exploitation

CVE-2022-34918

60Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 5.5%
from disclosure to weapon15 days
Published on NVDJul 4
1st PoC+15d
metasploitFeb 7
VulnCheck+968d
exploitation probability
5.5%top 8% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.