PT-2025-18638 · Linux+2 · Linux Kernel+2

Published

2025-05-01

·

Updated

2025-07-16

·

CVE-2022-49921

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use after free issue has been resolved in the Linux kernel's networking scheduler. The problem occurs because the skb cannot be used again after it is passed to qdisc enqueue(). This fix is similar to a previous commit that stored the skb length before calling the child enqueue function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05848
CVE-2022-49921
OESA-2025-1820
SUSE-SU-2025:01966-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:02334-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_02173-1
SUSE-SU-2025_02334-1

Affected Products

Astra Linux
Linux Kernel
Suse