logo

Exploiting nf_tables UAF (CVE-2022-32250)

ID: 99a4f62b-00fb-5c58-b179-bfe0eacd821b

STIX ID: report--99a4f62b-00fb-5c58-b179-bfe0eacd821b

Feed Name: NCC Research

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-08-01

...
...

This report documents a detailed analysis and exploit of CVE-2022-32250, a use-after-free in the Linux nf_tables netlink subsystem that allows a local attacker to achieve root via a complex chain of four UAFs. The authors describe vulnerability discovery, kernel structure layouts, exploitation primitives (user_key_payload, cgroup_fs_context, setxattr/FUSE), KASLR bypass using adjacent tty_struct leaks, and final control of a function pointer to overwrite modprobe_path and spawn a root shell; the write-up also includes the patch and disclosure timeline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.