cbcvebase.
CVE-2022-48933
published 2024-08-22

CVE-2022-48933: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memory leak during stateful obj update stateful objects can be…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.2th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memory leak during stateful obj update stateful objects can be updated from the control plane. The transaction logic allocates a temporary object for this purpose. The ->init function was called for this object, so plain kfree() leaks resources. We must call ->destroy function of the object. nft_obj_destroy does this, but it also decrements the module refcount, but the update path doesn't increment it. To avoid special-casing the update object release, do module_get for the update case too and release it via nft_obj_destroy().

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.12-1 (bookworm)linux 5.16.12-1 (bookworm)
linuxlinux
linuxlinux>= d62d0ba97b5803183e70cfded7f7b9da76893bf5 < 53026346a94c43f35c32b18804041bc483271d8753026346a94c43f35c32b18804041bc483271d87
linuxlinux>= d62d0ba97b5803183e70cfded7f7b9da76893bf5 < 7e9880e81d3fd6a43c202f2057174852904328267e9880e81d3fd6a43c202f205717485290432826
linuxlinux>= d62d0ba97b5803183e70cfded7f7b9da76893bf5 < e96e204ee6fa46702f6c94c3c69a09e69e0eac52e96e204ee6fa46702f6c94c3c69a09e69e0eac52
linuxlinux>= d62d0ba97b5803183e70cfded7f7b9da76893bf5 < 34bb90e407e3288f610558beaae54ecaa32b11c434bb90e407e3288f610558beaae54ecaa32b11c4
linuxlinux>= d62d0ba97b5803183e70cfded7f7b9da76893bf5 < dad3bdeef45f81a6e90204bcc85360bb76eccec7dad3bdeef45f81a6e90204bcc85360bb76eccec7
linuxlinux_kernel>= 0 < 5.10.103-15.10.103-1
linuxlinux_kernel>= 0 < 5.16.12-15.16.12-1
linuxlinux_kernel>= 0 < 5.16.12-15.16.12-1
linuxlinux_kernel>= 0 < 5.16.12-15.16.12-1
linuxlinux_kernel>= 5.11 < 5.15.265.15.26
linuxlinux_kernel>= 5.16 < 5.16.125.16.12
linuxlinux_kernel>= 5.4 < 5.4.1825.4.182
linuxlinux_kernel>= 5.5 < 5.10.1035.10.103

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.