CVE-2022-25636: Debian Linux

High severity, CVSS 7.8. EPSS: 2.6% chance of exploitation in the next 30 days.

net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 5.4, before 5.4.182 (fixed in 5.4.182); from 5.5, before 5.10.103 (fixed in 5.10.103); from 5.11, before 5.15.26 (fixed in 5.15.26); from 5.16, before 5.16.12 (fixed in 5.16.12)
  • Netapp h300e: affected versions not specified
  • Netapp h300s: affected versions not specified
  • Netapp h410c: affected versions not specified
  • Netapp h410s: affected versions not specified
  • Netapp h500e: affected versions not specified
  • Netapp h500s: affected versions not specified
  • Netapp h700e: affected versions not specified
  • Netapp h700s: affected versions not specified
  • Oracle Communications Cloud Native Core Binding Support Function: version 22.1.3 only
  • Oracle Communications Cloud Native Core Network Exposure Function: version 22.1.1 only
  • Oracle Communications Cloud Native Core Policy: version 22.2.0 only

Published 2022-02-24. Last modified 2026-06-17.