PT-2025-18635 · Linux+2 · Linux Kernel+2

Published

2022-10-31

·

Updated

2025-07-11

·

CVE-2022-49918

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability has been resolved in the Linux kernel. The issue occurs during the initialization of ip vs conn net init(), where if the file ip vs conn or ip vs conn sync fails to be created, the initialization is successful by default. As a result, the ip vs conn or ip vs conn sync file is not found during removal, leading to a WARNING in ip vs cleanup batch(). The stack information shows a call trace involving remove proc entry, ip vs cleanup batch, and other functions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Handling of Exceptional Conditions

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05780
CVE-2022-49918
OESA-2025-1820
SUSE-SU-2025:01966-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_02173-1

Affected Products

Astra Linux
Linux Kernel
Suse