CVE-2022-49919
published 2025-05-01CVE-2022-49919: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flow rule object from commit path No need to postpone this to…
PriorityP427high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: release flow rule object from commit path
No need to postpone this to the commit release path, since no packets
are walking over this object, this is accessed from control plane only.
This helped uncovered UAF triggered by races with the netlink notifier.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.8-1 (bookworm) | linux 6.0.8-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 330c0c6cd2150a2d7f47af16aa590078b0d2f736 < b2d7a92aff0fbd93c29d2aa6451fb99f050e2c4e | b2d7a92aff0fbd93c29d2aa6451fb99f050e2c4e |
| linux | linux | >= 5.10.122 < 5.10.154 | 5.10.154 |
| linux | linux | >= 5.15.47 < 5.15.78 | 5.15.78 |
| linux | linux | >= 5.17.15 < 5.18 | 5.18 |
| linux | linux | >= 5.18.4 < 5.19 | 5.19 |
| linux | linux | >= 5.4.198 < 5.4.224 | 5.4.224 |
| linux | linux | >= 5b8d63489c3b701eb2a76f848ec94d8cbc9373b9 < 74fd5839467054cd9c4d050614d3ee8788386171 | 74fd5839467054cd9c4d050614d3ee8788386171 |
| linux | linux | >= 9dd732e0bdf538b1b76dc7c157e2b5e560ff30d3 < 4ab6f96444e936f5e4a936d5c0bc948144bcded3 | 4ab6f96444e936f5e4a936d5c0bc948144bcded3 |
| linux | linux | >= 9dd732e0bdf538b1b76dc7c157e2b5e560ff30d3 < 26b5934ff4194e13196bedcba373cd4915071d0e | 26b5934ff4194e13196bedcba373cd4915071d0e |
| linux | linux | >= e33d9bd563e71f6c6528b96008d65524a459c4dc < 6044791b7be707fd0e709f26e961a446424e5051 | 6044791b7be707fd0e709f26e961a446424e5051 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.8-1 | 6.0.8-1 |
| linux | linux_kernel | >= 0 < 6.0.8-1 | 6.0.8-1 |
| linux | linux_kernel | >= 0 < 6.0.8-1 | 6.0.8-1 |
| linux | linux_kernel | >= 5.10.122 < 5.10.154 | 5.10.154 |
| linux | linux_kernel | >= 5.15.47 < 5.15.78 | 5.15.78 |
| linux | linux_kernel | >= 5.17.15 < 5.18 | 5.18 |
| linux | linux_kernel | >= 5.18.4 < 6.0.8 | 6.0.8 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3mh8-97g4-p2mv: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: release flow rule object from commit path
No need to postp
ghsa_unreviewed·2025-05-01
CVE-2022-49919 [HIGH] CWE-362 GHSA-3mh8-97g4-p2mv: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: release flow rule object from commit path
No need to postp
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: release flow rule object from commit path
No need to postpone this to the commit release path, since no packets
are walking over this object, this is accessed from control plane only.
This helped uncovered UAF triggered by races with the netlink notifier.
OSV
CVE-2022-49919: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flow rule object from commit path No need to postpon
osv·2025-05-01·CVSS 7.0
CVE-2022-49919 [HIGH] CVE-2022-49919: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flow rule object from commit path No need to postpon
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flow rule object from commit path No need to postpone this to the commit release path, since no packets are walking over this object, this is accessed from control plane only. This helped uncovered UAF triggered by races with the netlink notifier.
Red Hat
kernel: netfilter: nf_tables: release flow rule object from commit path
vendor_redhat·2025-05-01·CVSS 7.0
CVE-2022-49919 [HIGH] kernel: netfilter: nf_tables: release flow rule object from commit path
kernel: netfilter: nf_tables: release flow rule object from commit path
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: release flow rule object from commit path
No need to postpone this to the commit release path, since no packets
are walking over this object, this is accessed from control plane only.
This helped uncovered UAF triggered by races with the netlink notifier.
Statement: A use-after-free vulnerability was identified in the nf_tables subsystem of the Linux kernel. The flow rule object was previously released too late during the commit release path, which could result in race conditions when netlink notifications are processed concurrently. The fix moves the destruction of the flow rule earlier in the commit phase to eliminate the wind
Debian
CVE-2022-49919: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
vendor_debian·2022·CVSS 7.0
CVE-2022-49919 [HIGH] CVE-2022-49919: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flow rule object from commit path No need to postpone this to the commit release path, since no packets are walking over this object, this is accessed from control plane only. This helped uncovered UAF triggered by races with the netlink notifier.
Scope: local
bookworm: resolved (fixed in 6.0.8-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: resolved (fixed in 6.0.8-1)
sid: resolved (fixed in 6.0.8-1)
trixie: resolved (fixed in 6.0.8-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/26b5934ff4194e13196bedcba373cd4915071d0ehttps://git.kernel.org/stable/c/4ab6f96444e936f5e4a936d5c0bc948144bcded3https://git.kernel.org/stable/c/6044791b7be707fd0e709f26e961a446424e5051https://git.kernel.org/stable/c/74fd5839467054cd9c4d050614d3ee8788386171https://git.kernel.org/stable/c/b2d7a92aff0fbd93c29d2aa6451fb99f050e2c4e
2025-05-01
Published