In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: release flow rule object from commit path
No need to postpone this to the commit release path, since no packets
are walking over this object, this is accessed from control plane only.
This helped uncovered UAF triggered by races with the netlink notifier.
References
Configurations
Configuration 1 (hide)
|
History
07 May 2025, 13:27
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.1:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.1:rc3:*:*:*:*:*:* |
|
First Time |
Linux linux Kernel
Linux |
|
References | () https://git.kernel.org/stable/c/26b5934ff4194e13196bedcba373cd4915071d0e - Patch | |
References | () https://git.kernel.org/stable/c/4ab6f96444e936f5e4a936d5c0bc948144bcded3 - Patch | |
References | () https://git.kernel.org/stable/c/6044791b7be707fd0e709f26e961a446424e5051 - Patch | |
References | () https://git.kernel.org/stable/c/74fd5839467054cd9c4d050614d3ee8788386171 - Patch | |
References | () https://git.kernel.org/stable/c/b2d7a92aff0fbd93c29d2aa6451fb99f050e2c4e - Patch | |
CWE | CWE-362 CWE-416 |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.0 |
02 May 2025, 13:52
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
01 May 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-01 15:16
Updated : 2025-05-07 13:27
NVD link : CVE-2022-49919
Mitre link : CVE-2022-49919
CVE.ORG link : CVE-2022-49919
JSON object : View
Products Affected
linux
- linux_kernel