PT-2025-18636 · Linux+1 · Linux Kernel+1

Published

2025-05-01

·

Updated

2025-05-02

·

CVE-2022-49919

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns a use-after-free (UAF) bug in the Linux kernel's netfilter nf tables component. This UAF is triggered by races with the netlink notifier. The problem arises because the flow rule object is released from the commit path, but it is accessed from the control plane only, with no packets walking over this object.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06051
CVE-2022-49919

Affected Products

Astra Linux
Linux Kernel