net/netfilter/nftablesapi.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFTSTATEFULEXPR check leads to a use-after-free.
{ "urgency": "not yet assigned" }