CVE-2022-49561

CRITICAL

Linux Kernel 4.7-5.18.2 Netfilter Conntrack Use-After-Free

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: re-fetch conntrack after insertion In case the conntrack is clashing, insertion can free skb->_nfct and set skb->_nfct to the already-confirmed entry. This wasn't found before because the conntrack entry and the extension space used to free'd after an rcu grace period, plus the race needs events enabled to trigger.

Scores

CVSS v3 9.8
EPSS 0.0081
EPSS Percentile 53.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (26)
linux/Kernel 4.15.0 - 4.19.246linux
linux/Kernel 4.20.0 - 5.4.197linux
linux/Kernel 4.7.0 - 4.14.282linux
linux/Kernel 5.11.0 - 5.15.45linux
linux/Kernel 5.16.0 - 5.17.13linux
linux/Kernel 5.18.0 - 5.18.2linux
linux/Kernel 5.5.0 - 5.10.120linux
Linux/Linux < 4.7
Linux/Linux 4.14.282 - 4.14.*
Linux/Linux 4.19.246 - 4.19.*
... and 16 more
Published Feb 26, 2025
Tracked Since Feb 18, 2026