CVE-2022-49358

Source
https://cve.org/CVERecord?id=CVE-2022-49358
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49358.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-49358
Downstream
Published
2025-02-26T02:11:07Z
Modified
2026-08-12T03:51:09Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
netfilter: nf_tables: memleak flow rule from commit path
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: memleak flow rule from commit path

Abort path release flow rule object, however, commit path does not. Update code to destroy these objects before releasing the transaction.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49358.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c9626a2cbdb20e26587b3fad99960520a023432b
Fixed
5b8d63489c3b701eb2a76f848ec94d8cbc9373b9
Fixed
330c0c6cd2150a2d7f47af16aa590078b0d2f736
Fixed
e33d9bd563e71f6c6528b96008d65524a459c4dc
Fixed
80de9ea1f5b808a6601e91111fae601df2b26369
Fixed
ab9f34a30c23f656e76f4c5b83125a4e7b53c86e
Fixed
9dd732e0bdf538b1b76dc7c157e2b5e560ff30d3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49358.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
5.4.198
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.122
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.47
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.17.15
Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
5.18.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49358.json"