CVE-2022-49921

Source
https://cve.org/CVERecord?id=CVE-2022-49921
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49921.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-49921
Downstream
CLSA (2)
DEBIAN (1)
OESA (1)
SUSE (4)
UBUNTU (1)
Related
Published
2025-05-01T14:11:00Z
Modified
2026-10-08T02:48:07Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net: sched: Fix use after free in red_enqueue()
Details

In the Linux kernel, the following vulnerability has been resolved:

net: sched: Fix use after free in red_enqueue()

We can't use "skb" again after passing it to qdisc_enqueue(). This is basically identical to commit 2f09707d0c97 ("sch_sfb: Also store skb len before calling child enqueue").

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49921.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d7f4f332f082c4d4ba53582f902ed6b44fd6f45e
Fixed
795afe0b9bb6c915f0299a8e309936519be01619
Fixed
a238cdcf2bdc72207c74375fc8be13ee549ca9db
Fixed
e877f8fa49fbccc63cb2df2e9179bddc695b825a
Fixed
52e0429471976785c155bfbf51d80990c6cd46e2
Fixed
5960b9081baca85cc7dcb14aec1de85999ea9d36
Fixed
fc4b50adb400ee5ec527a04073174e8e73a139fa
Fixed
170e5317042c302777ed6d59fdb84af9b0219d4e
Fixed
8bdc2acd420c6f3dd1f1c78750ec989f02a1e2b9
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4.4.163
Fixed
4.5
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ab0b3b9dbf559a5633d460e748144697bd2d3aa3

Affected versions

v4.*
v4.4.163
v4.4.164
v4.4.165
v4.4.166
v4.4.167
v4.4.168
v4.4.169
v4.4.170
v4.4.171
v4.4.172
v4.4.173
v4.4.174
v4.4.175
v4.4.176
v4.4.177
v4.4.178
v4.4.179
v4.4.180
v4.4.181
v4.4.182
v4.4.183
v4.4.184
v4.4.185
v4.4.186
v4.4.187
v4.4.188
v4.4.189
v4.4.190
v4.4.191
v4.4.192
v4.4.193
v4.4.194
v4.4.195
v4.4.196
v4.4.197
v4.4.198
v4.4.199
v4.4.200
v4.4.201
v4.4.202
v4.4.203
v4.4.204
v4.4.205
v4.4.206
v4.4.207
v4.4.208
v4.4.209
v4.4.210
v4.4.211
v4.4.212
v4.4.213
v4.4.214
v4.4.215
v4.4.216
v4.4.217
v4.4.218
v4.4.219
v4.4.220
v4.4.221
v4.4.222
v4.4.223
v4.4.224
v4.4.225
v4.4.226
v4.4.227
v4.4.228
v4.4.229
v4.4.230
v4.4.231
v4.4.232
v4.4.233
v4.4.234
v4.4.235
v4.4.236
v4.4.237
v4.4.238
v4.4.239
v4.4.240
v4.4.241
v4.4.242
v4.4.243
v4.4.244
v4.4.245
v4.4.246
v4.4.247
v4.4.248
v4.4.249
v4.4.250
v4.4.251
v4.4.252
v4.4.253
v4.4.254
v4.4.255
v4.4.256
v4.4.257
v4.4.258
v4.4.259
v4.4.260
v4.4.261
v4.4.262
v4.4.263
v4.4.264
v4.4.265
v4.4.266
v4.4.267
v4.4.268
v4.4.269
v4.4.270
v4.4.271
v4.4.272
v4.4.273
v4.4.274
v4.4.275
v4.4.276
v4.4.277
v4.4.278
v4.4.279
v4.4.280
v4.4.281
v4.4.282
v4.4.283
v4.4.284
v4.4.285
v4.4.286
v4.4.287
v4.4.288
v4.4.289
v4.4.290
v4.4.291
v4.4.292
v4.4.293
v4.4.294
v4.4.295
v4.4.296
v4.4.297
v4.4.298
v4.4.299
v4.4.300
v4.4.301
v4.4.302

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49921.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
4.9.333
Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
4.14.299
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.265
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.224
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.154
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.78
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.0.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49921.json"