Exploitable vulnerabilities identified in the Linux kernel for POSIX CPU timer, cls_route, and nf_tables

Several vulnerabilities have been identified in the Linux kernel, caused by access to already freed memory areas, allowing a local user to elevate their privileges within the system. Working prototypes of exploits for all the identified issues have been created and will be published a week after the vulnerabilities are disclosed. Patches addressing these issues have been sent to the Linux kernel developers.

  • CVE-2022-2588 is a vulnerability in the implementation of the cls_route filter, caused by an error that prevents the old filter from being removed from the hash table until the memory is cleared when processing a null descriptor. The vulnerability has been present since the release 2.6.12-rc2. To conduct an attack, CAP_NET_ADMIN rights are required, which can be obtained with access to create network namespaces or user namespaces. A workaround to protect against this is to disable the cls_route module by adding the line ‘install cls_route /bin/true’ to modprobe.conf.
  • CVE-2022-2586 is a vulnerability in the netfilter subsystem in the nf_tables module, which enables the nftables packet filtering. The issue arises because the nft object may reference a set-list in another table, leading to access to freed memory after that table is deleted. The vulnerability has been present since the release 3.16-rc1. To conduct an attack, CAP_NET_ADMIN rights are needed, which can be obtained with access to create network namespaces or user namespaces.
  • CVE-2022-2585 is a vulnerability in the POSIX CPU timer, caused by the timer structure remaining in the list when called from a non-leading thread, despite the memory allocated for storage being cleared. This vulnerability has been present since the release 3.16-rc1.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster