cbcvebase.
CVE-2022-49698
published 2025-02-26

CVE-2022-49698: In the Linux kernel, the following vulnerability has been resolved: netfilter: use get_random_u32 instead of prandom bh might occur while updating per-cpu…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.0th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: use get_random_u32 instead of prandom bh might occur while updating per-cpu rnd_state from user context, ie. local_out path. BUG: using smp_processor_id() in preemptible [00000000] code: nginx/2725 caller is nft_ng_random_eval+0x24/0x54 [nft_numgen] Call Trace: check_preemption_disabled+0xde/0xe0 nft_ng_random_eval+0x24/0x54 [nft_numgen] Use the random driver instead, this also avoids need for local prandom state. Moreover, prandom now uses the random driver since d4150779e60f ("random32: use real rng for non-deterministic randomness"). Based on earlier patch from Pablo Neira.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 978d8f9055c3a7c35db2ac99cd2580b993396e33 < 15cc30ac2a8d7185f8ebf97dd1ddd90a7c79783b15cc30ac2a8d7185f8ebf97dd1ddd90a7c79783b
linuxlinux>= 978d8f9055c3a7c35db2ac99cd2580b993396e33 < d0906b0fffc9f19bc42708ca3e84e2089088386cd0906b0fffc9f19bc42708ca3e84e2089088386c
linuxlinux>= 978d8f9055c3a7c35db2ac99cd2580b993396e33 < 6ce71f83f798be7e1ca68707fec449fbecb388526ce71f83f798be7e1ca68707fec449fbecb38852
linuxlinux>= 978d8f9055c3a7c35db2ac99cd2580b993396e33 < b1fd94e704571f98b21027340eecf821b2bdffbab1fd94e704571f98b21027340eecf821b2bdffba
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.4.0-225.2455.4.0-225.245
linuxlinux_kernel>= 4.18 < 5.10.1275.10.127
linuxlinux_kernel>= 5.11 < 5.15.515.15.51
linuxlinux_kernel>= 5.16 < 5.18.85.18.8
ubuntulinux-bluefield

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.