CVE-2022-49358

MEDIUM

Linux Kernel 5.3-5.18.3 Use-After-Free in Netfilter Flow Rule Commit Path

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: memleak flow rule from commit path Abort path release flow rule object, however, commit path does not. Update code to destroy these objects before releasing the transaction.

Scores

CVSS v3 5.5
EPSS 0.0027
EPSS Percentile 18.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (21)
linux/Kernel 5.11.0 - 5.15.47linux
linux/Kernel 5.16.0 - 5.17.15linux
linux/Kernel 5.18.0 - 5.18.4linux
linux/Kernel 5.3.0 - 5.4.198linux
linux/Kernel 5.5.0 - 5.10.122linux
Linux/Linux < 5.3
Linux/Linux 5.10.122 - 5.10.*
Linux/Linux 5.15.47 - 5.15.*
Linux/Linux 5.17.15 - 5.17.*
Linux/Linux 5.18.4 - 5.18.*
... and 11 more
Published Feb 26, 2025
Tracked Since Feb 18, 2026