IT

Tracker / CVE-2022-49919

CVE-2022-49919

High 7.8

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flow rule object from commit path No need to postpone this to the commit release path, since no packets are walking over this object, this is accessed from control plane only. This helped uncovered UAF triggered by races with the netlink notifier.

Affected products and versions

linux linux_kernel
linux linux_kernel · 5.10.122 → 5.10.154
linux linux_kernel · 5.15.47 → 5.15.78
linux linux_kernel · 5.17.15 → 5.18
linux linux_kernel · 5.18.4 → 6.0.8
linux linux_kernel · 5.4.198 → 5.4.224

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References