CVE-2022-49358
published 2025-02-26CVE-2022-49358: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: memleak flow rule from commit path Abort path release flow rule…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: memleak flow rule from commit path
Abort path release flow rule object, however, commit path does not.
Update code to destroy these objects before releasing the transaction.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.5-1 (bookworm) | linux 5.18.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= c9626a2cbdb20e26587b3fad99960520a023432b < 5b8d63489c3b701eb2a76f848ec94d8cbc9373b9 | 5b8d63489c3b701eb2a76f848ec94d8cbc9373b9 |
| linux | linux | >= c9626a2cbdb20e26587b3fad99960520a023432b < 330c0c6cd2150a2d7f47af16aa590078b0d2f736 | 330c0c6cd2150a2d7f47af16aa590078b0d2f736 |
| linux | linux | >= c9626a2cbdb20e26587b3fad99960520a023432b < e33d9bd563e71f6c6528b96008d65524a459c4dc | e33d9bd563e71f6c6528b96008d65524a459c4dc |
| linux | linux | >= c9626a2cbdb20e26587b3fad99960520a023432b < 80de9ea1f5b808a6601e91111fae601df2b26369 | 80de9ea1f5b808a6601e91111fae601df2b26369 |
| linux | linux | >= c9626a2cbdb20e26587b3fad99960520a023432b < ab9f34a30c23f656e76f4c5b83125a4e7b53c86e | ab9f34a30c23f656e76f4c5b83125a4e7b53c86e |
| linux | linux | >= c9626a2cbdb20e26587b3fad99960520a023432b < 9dd732e0bdf538b1b76dc7c157e2b5e560ff30d3 | 9dd732e0bdf538b1b76dc7c157e2b5e560ff30d3 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.127-1 | 5.10.127-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 5.11 < 5.15.47 | 5.15.47 |
| linux | linux_kernel | >= 5.16 < 5.17.15 | 5.17.15 |
| linux | linux_kernel | >= 5.18 < 5.18.4 | 5.18.4 |
| linux | linux_kernel | >= 5.3 < 5.4.198 | 5.4.198 |
| linux | linux_kernel | >= 5.5 < 5.10.122 | 5.10.122 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: netfilter: nf_tables: memleak flow rule from commit path
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49358 [MEDIUM] CWE-401 kernel: netfilter: nf_tables: memleak flow rule from commit path
kernel: netfilter: nf_tables: memleak flow rule from commit path
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: memleak flow rule from commit path
Abort path release flow rule object, however, commit path does not.
Update code to destroy these objects before releasing the transaction.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 8) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Pac
Debian
CVE-2022-49358: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
vendor_debian·2022·CVSS 5.5
CVE-2022-49358 [MEDIUM] CVE-2022-49358: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: memleak flow rule from commit path Abort path release flow rule object, however, commit path does not. Update code to destroy these objects before releasing the transaction.
Scope: local
bookworm: resolved (fixed in 5.18.5-1)
bullseye: resolved (fixed in 5.10.127-1)
forky: resolved (fixed in 5.18.5-1)
sid: resolved (fixed in 5.18.5-1)
trixie: resolved (fixed in 5.18.5-1)
GHSA
GHSA-xg42-33mc-4587: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: memleak flow rule from commit path
Abort path release flow
ghsa_unreviewed·2025-04-14
CVE-2022-49358 [MEDIUM] CWE-401 GHSA-xg42-33mc-4587: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: memleak flow rule from commit path
Abort path release flow
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: memleak flow rule from commit path
Abort path release flow rule object, however, commit path does not.
Update code to destroy these objects before releasing the transaction.
OSV
CVE-2022-49358: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: memleak flow rule from commit path Abort path release flow r
osv·2025-02-26·CVSS 5.5
CVE-2022-49358 [MEDIUM] CVE-2022-49358: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: memleak flow rule from commit path Abort path release flow r
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: memleak flow rule from commit path Abort path release flow rule object, however, commit path does not. Update code to destroy these objects before releasing the transaction.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/330c0c6cd2150a2d7f47af16aa590078b0d2f736https://git.kernel.org/stable/c/5b8d63489c3b701eb2a76f848ec94d8cbc9373b9https://git.kernel.org/stable/c/80de9ea1f5b808a6601e91111fae601df2b26369https://git.kernel.org/stable/c/9dd732e0bdf538b1b76dc7c157e2b5e560ff30d3https://git.kernel.org/stable/c/ab9f34a30c23f656e76f4c5b83125a4e7b53c86ehttps://git.kernel.org/stable/c/e33d9bd563e71f6c6528b96008d65524a459c4dc
2025-02-26
Published