CVE-2022-49561
CRITICALLinux Kernel 4.7-5.18.2 Netfilter Conntrack Use-After-Free
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: re-fetch conntrack after insertion In case the conntrack is clashing, insertion can free skb->_nfct and set skb->_nfct to the already-confirmed entry. This wasn't found before because the conntrack entry and the extension space used to free'd after an rcu grace period, plus the race needs events enabled to trigger.
References (8)
Core 8
Core References
Scores
CVSS v3
9.8
EPSS
0.0081
EPSS Percentile
53.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (26)
linux/Kernel
4.15.0 - 4.19.246linux
linux/Kernel
4.20.0 - 5.4.197linux
linux/Kernel
4.7.0 - 4.14.282linux
linux/Kernel
5.11.0 - 5.15.45linux
linux/Kernel
5.16.0 - 5.17.13linux
linux/Kernel
5.18.0 - 5.18.2linux
linux/Kernel
5.5.0 - 5.10.120linux
Linux/Linux
< 4.7
Linux/Linux
4.14.282 - 4.14.*
Linux/Linux
4.19.246 - 4.19.*
... and 16 more
Published
Feb 26, 2025
Tracked Since
Feb 18, 2026