CVE-2022-2586

Executive Summary

CVE-2022-2586 exposes a use‑after‑free in Linux nftables: an nft object or expression may reference a set from a different nft table. When the referenced table is deleted, the dangling reference can trigger a kernel crash or allow privilege escalation. The vulnerability is actively exploited in the wild (CISA KEV).


Authoritative CVE Metadata - CVSS Base Score: 5.3 (MEDIUM) - Published: 2024-01-08T18:15:44.620 - Last Modified: 2026-08-20T14:17:08.057

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2024-06-26)

Original Description: It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

"True silence is the rest of the mind; it is to the spirit what sleep is to the body, nourishment and refreshment."

— William Penn
Source: NVD