CVE-2022-2586
Linux Kernel Use-After-Free Vulnerability
- Published
- Jan 8, 2024
- Updated
- Aug 20, 2026
- Assigning CNA
- canonical
- Evidence observed
- Jun 26, 2024
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 95.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
Sources
5- CVE-2022-2586-LPEExploit
CVE-2022-2586: Linux kernel nft_object UAF
- CVE-2022-2586Exploit
Local privilege escalation exploit for CVE-2022-2586 targeting Linux kernel 5.15.0-25 on Ubuntu 22.04, written in C and compiled with gcc.
- 2022-LPE-UAFExploit
Proof-of-concept exploit code for Linux kernel use-after-free vulnerabilities (CVE-2022-2585, CVE-2022-2586, CVE-2022-2588) enabling local privilege escalation, with references to DirtyCred research paper.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.