cbcvebase.
CVE-2022-49183
published 2025-02-26

CVE-2022-49183: In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix ref leak when switching zones When switching zones or network…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
18.2th percentile
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix ref leak when switching zones When switching zones or network namespaces without doing a ct clear in between, it is now leaking a reference to the old ct entry. That's because tcf_ct_skb_nfct_cached() returns false and tcf_ct_flow_table_lookup() may simply overwrite it. The fix is to, as the ct entry is not reusable, free it already at tcf_ct_skb_nfct_cached().

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 0fc1847359964e95e521cf2bb2b10f8e33dd0970 < 9222a08be539cbb7a8e0d46cbc7ab9e4db273eb89222a08be539cbb7a8e0d46cbc7ab9e4db273eb8
linuxlinux>= 2f131de361f6d0eaff17db26efdb844c178432f8 < b24793a37d91aacad7cb9893b226a7924a89636ab24793a37d91aacad7cb9893b226a7924a89636a
linuxlinux>= 2f131de361f6d0eaff17db26efdb844c178432f8 < bcb74e132a76ce0502bb33d5b65533a4ed72d159bcb74e132a76ce0502bb33d5b65533a4ed72d159
linuxlinux>= 5.10.103 < 5.10.2585.10.258
linuxlinux>= 5.15.26 < 5.15.335.15.33
linuxlinux>= 5.16.12 < 5.16.195.16.19
linuxlinux>= a95ea90deb3071c1ded77a05e91cfebc5238d908 < bcbf4e5c3b5b373cd61528392dd1ec8e9c0fd33dbcbf4e5c3b5b373cd61528392dd1ec8e9c0fd33d
linuxlinux>= e9408de00e5ecd0dbe91cf061c7da23711c4febb < 4bb42d73def9411e5cad885b9811987d72431df14bb42d73def9411e5cad885b9811987d72431df1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 5.10.103 < 5.115.11
linuxlinux_kernel>= 5.15.26 < 5.15.335.15.33
linuxlinux_kernel5.16.12 – 5.16.19
linuxlinux_kernel5.17 – 5.17.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.