cbcvebase.
CVE-2022-50001
published 2025-06-18

CVE-2022-50001: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tproxy: restrict to prerouting hook TPROXY is only allowed from prerouting…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.6th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tproxy: restrict to prerouting hook TPROXY is only allowed from prerouting, but nft_tproxy doesn't check this. This fixes a crash (null dereference) when using tproxy from e.g. output.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= 4ed8eb6570a49931c705512060acd50058d61616 < 0b21edf4cc13516716848e0a4fdf726aa2a62cd90b21edf4cc13516716848e0a4fdf726aa2a62cd9
linuxlinux>= 4ed8eb6570a49931c705512060acd50058d61616 < 83ef55c4281f1b4c6bd4457c2e96ccd1c9e8020083ef55c4281f1b4c6bd4457c2e96ccd1c9e80200
linuxlinux>= 4ed8eb6570a49931c705512060acd50058d61616 < eaba3f9b672c3a3f820da8ee9584b9520674eafaeaba3f9b672c3a3f820da8ee9584b9520674eafa
linuxlinux>= 4ed8eb6570a49931c705512060acd50058d61616 < 9a1d92cbeac3335fee99fa865b8c5b0f2e71a8f79a1d92cbeac3335fee99fa865b8c5b0f2e71a8f7
linuxlinux>= 4ed8eb6570a49931c705512060acd50058d61616 < 343fed6b0daeb528ae5c9d4d84d9ff763ac95619343fed6b0daeb528ae5c9d4d84d9ff763ac95619
linuxlinux>= 4ed8eb6570a49931c705512060acd50058d61616 < 18bbc3213383a82b05383827f4b1b882e3f0a5a518bbc3213383a82b05383827f4b1b882e3f0a5a5
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 4.19 < 4.19.2734.19.273
linuxlinux_kernel>= 4.20 < 5.4.2325.4.232
linuxlinux_kernel>= 5.11 < 5.15.955.15.95
linuxlinux_kernel>= 5.16 < 5.19.65.19.6
linuxlinux_kernel>= 5.5 < 5.10.1695.10.169

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.