cbcvebase.
CVE-2022-49110
published 2025-02-26

CVE-2022-49110: In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: revisit gc autotuning as of commit 4608fdfc07e1 ("netfilter…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.58%
44.6th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: revisit gc autotuning as of commit 4608fdfc07e1 ("netfilter: conntrack: collect all entries in one cycle") conntrack gc was changed to run every 2 minutes. On systems where conntrack hash table is set to large value, most evictions happen from gc worker rather than the packet path due to hash table distribution. This causes netlink event overflows when events are collected. This change collects average expiry of scanned entries and reschedules to the average remaining value, within 1 to 60 second interval. To avoid event overflows, reschedule after each bucket and add a limit for both run time and number of evictions per run. If more entries have to be evicted, reschedule and restart 1 jiffy into the future.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.19.206 < 4.204.20
linuxlinux>= 4608fdfc07e116f9fc0895beb40abad7cdb5ee3d < 58d52743ae85d28c9335c6034d6ce350b868995158d52743ae85d28c9335c6034d6ce350b8689951
linuxlinux>= 4608fdfc07e116f9fc0895beb40abad7cdb5ee3d < 7cd361d5e6d986c0d4cafb9ceaa803359048ae157cd361d5e6d986c0d4cafb9ceaa803359048ae15
linuxlinux>= 4608fdfc07e116f9fc0895beb40abad7cdb5ee3d < 592e57591826f3d09c28d755a39ea8e9d13705ad592e57591826f3d09c28d755a39ea8e9d13705ad
linuxlinux>= 4608fdfc07e116f9fc0895beb40abad7cdb5ee3d < 2cfadb761d3d0219412fd8150faea60c7e8638332cfadb761d3d0219412fd8150faea60c7e863833
linuxlinux>= 5.10.62 < 5.115.11
linuxlinux>= 5.13.14 < 5.145.14
linuxlinux>= 5.4.144 < 5.55.5
linuxlinux_kernel< 5.15.345.15.34
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 5.16 < 5.16.205.16.20
linuxlinux_kernel>= 5.17 < 5.17.35.17.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.