Skip to content
Privilege Escalation Vulnerability in Netfilter Kernel Module

Privilege Escalation Vulnerability in Netfilter Kernel Module

First seen 28 Sep 2026, 19:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 20:08 UTC
  • •CVE-2022-25636 allows privilege escalation in netfilter kernel module.
  • •Exploitation requires SYS_ADMIN privileges and has a success rate below 50%.
  • •Users should update their kernel to mitigate the vulnerability.

CVE-2022-25636 is a privilege escalation vulnerability in the netfilter kernel module, identified on February 22, 2022. It allows users with SYS_ADMIN privileges to exploit a heap overflow due to a lack of boundary checks in the nft_fwd_dup_netdev_offload function. This vulnerability affects systems running the netfilter module in Linux kernel versions that include the flawed code. The exploit can lead to unauthorized privilege escalation, but success rates are reported to be less than 50%. Users are advised to update their kernel to mitigate this risk. The vulnerability was first publicly demonstrated through a proof-of-concept on March 7, 2022. Current status indicates ongoing concerns regarding its exploitation potential, particularly in environments where the netfilter module is utilized.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2022-02-22
CVE-2022-25636 published
A privilege escalation vulnerability in the netfilter kernel module was disclosed.
Sploitus
2022-03-07
First public PoC released
A proof-of-concept for CVE-2022-25636 was made publicly available, demonstrating the exploit.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2022-25636 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed