PT-2025-8111 · Linux+3 · Linux Kernel+3
Florian Westphal
·
Published
2022-01-01
·
Updated
2026-03-14
·
CVE-2022-49183
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A reference leak occurs in the Linux kernel when switching zones or network namespaces without clearing the connection tracking (ct) entry in between. This happens because
tcf ct skb nfct cached() returns false and tcf ct flow table lookup() may overwrite the old ct entry. The issue arises from the ct entry not being reusable.Recommendations
To resolve the issue, apply the fix that frees the ct entry at
tcf ct skb nfct cached() to prevent reference leaks when switching zones or network namespaces.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Debian
Linux Kernel
Suse