EXPOSURES › CVE-2022-2586
CVE-2022-2586
HIGH ⌖ ON CISA KEV · EXPLOITEDLinux kernel use-after-free vulnerability in nft_object allows local privilege escalation.
This local privilege escalation vulnerability in the Linux kernel nft_object module enables attackers to bypass security controls on affected systems. DIB organizations must ensure all Linux-based systems are patched immediately to prevent unauthorized access and maintain NIST 800-171 compliance.
Shame score — A known kernel vulnerability that was actively exploited but did not involve vendor negligence or supply chain compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges.