CVE-2022-49920
published 2025-05-01CVE-2022-49920: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: netlink notifier might race to release objects commit release path is…
PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.14%
3.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: netlink notifier might race to release objects
commit release path is invoked via call_rcu and it runs lockless to
release the objects after rcu grace period. The netlink notifier handler
might win race to remove objects that the transaction context is still
referencing from the commit release path.
Call rcu_barrier() to ensure pending rcu callbacks run to completion
if the list of transactions to be destroyed is not empty.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.8-1 (bookworm) | linux 6.0.8-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 6001a930ce0378b62210d4f83583fc88a903d89d < 1ffe7100411a8b9015115ce124cd6c9c9da6f8e3 | 1ffe7100411a8b9015115ce124cd6c9c9da6f8e3 |
| linux | linux | >= 6001a930ce0378b62210d4f83583fc88a903d89d < e40b7c44d19e327ad8b49a491ef1fa8dcc4566e0 | e40b7c44d19e327ad8b49a491ef1fa8dcc4566e0 |
| linux | linux | >= 6001a930ce0378b62210d4f83583fc88a903d89d < d4bc8271db21ea9f1c86a1ca4d64999f184d4aae | d4bc8271db21ea9f1c86a1ca4d64999f184d4aae |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.0.8-1 | 6.0.8-1 |
| linux | linux_kernel | >= 0 < 6.0.8-1 | 6.0.8-1 |
| linux | linux_kernel | >= 0 < 6.0.8-1 | 6.0.8-1 |
| linux | linux_kernel | >= 5.12 < 5.15.78 | 5.15.78 |
| linux | linux_kernel | >= 5.16 < 6.0.8 | 6.0.8 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: netfilter: nf_tables: netlink notifier might race to release objects
vendor_redhat·2025-05-01·CVSS 4.7
CVE-2022-49920 [MEDIUM] kernel: netfilter: nf_tables: netlink notifier might race to release objects
kernel: netfilter: nf_tables: netlink notifier might race to release objects
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: netlink notifier might race to release objects
commit release path is invoked via call_rcu and it runs lockless to
release the objects after rcu grace period. The netlink notifier handler
might win race to remove objects that the transaction context is still
referencing from the commit release path.
Call rcu_barrier() to ensure pending rcu callbacks run to completion
if the list of transactions to be destroyed is not empty.
Statement: The bug could happen only when qdisc with child qdiscs like netem or codel being used.
Mitigation: To mitigate this issue, prevent module sch_hfsc from being loaded. Please see https://access
Debian
CVE-2022-49920: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
vendor_debian·2022·CVSS 4.7
CVE-2022-49920 [MEDIUM] CVE-2022-49920: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: netlink notifier might race to release objects commit release path is invoked via call_rcu and it runs lockless to release the objects after rcu grace period. The netlink notifier handler might win race to remove objects that the transaction context is still referencing from the commit release path. Call rcu_barrier() to ensure pending rcu callbacks run to completion if the list of transactions to be destroyed is not empty.
Scope: local
bookworm: resolved (fixed in 6.0.8-1)
bullseye: resolved
forky: resolved (fixed in 6.0.8-1)
sid: resolved (fixed in 6.0.8-1)
trixie: resolved (fixed in 6.0.8-1)
GHSA
GHSA-8r5m-9xx4-3v9j: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: netlink notifier might race to release objects
commit rele
ghsa_unreviewed·2025-05-01
CVE-2022-49920 [MEDIUM] CWE-362 GHSA-8r5m-9xx4-3v9j: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: netlink notifier might race to release objects
commit rele
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: netlink notifier might race to release objects
commit release path is invoked via call_rcu and it runs lockless to
release the objects after rcu grace period. The netlink notifier handler
might win race to remove objects that the transaction context is still
referencing from the commit release path.
Call rcu_barrier() to ensure pending rcu callbacks run to completion
if the list of transactions to be destroyed is not empty.
OSV
CVE-2022-49920: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: netlink notifier might race to release objects commit releas
osv·2025-05-01·CVSS 4.7
CVE-2022-49920 [MEDIUM] CVE-2022-49920: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: netlink notifier might race to release objects commit releas
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: netlink notifier might race to release objects commit release path is invoked via call_rcu and it runs lockless to release the objects after rcu grace period. The netlink notifier handler might win race to remove objects that the transaction context is still referencing from the commit release path. Call rcu_barrier() to ensure pending rcu callbacks run to completion if the list of transactions to be destroyed is not empty.
No detection rules found.
No public exploits indexed.
2025-05-01
Published