CVE-2022-49920 (GCVE-0-2022-49920)
Vulnerability from cvelistv5
Published
2025-05-01 14:10
Modified
2026-08-05 08:56
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: netlink notifier might race to release objects commit release path is invoked via call_rcu and it runs lockless to release the objects after rcu grace period. The netlink notifier handler might win race to remove objects that the transaction context is still referencing from the commit release path. Call rcu_barrier() to ensure pending rcu callbacks run to completion if the list of transactions to be destroyed is not empty.
Impacted products
Vendor Product Version
Linux Linux Version: 6001a930ce0378b62210d4f83583fc88a903d89d
Version: 6001a930ce0378b62210d4f83583fc88a903d89d
Version: 6001a930ce0378b62210d4f83583fc88a903d89d
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "HIGH",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 4.7,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2022-49920",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-01T14:58:43.450275Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-362",
                "description": "CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-01T14:58:46.228Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/netfilter/nf_tables_api.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "1ffe7100411a8b9015115ce124cd6c9c9da6f8e3",
              "status": "affected",
              "version": "6001a930ce0378b62210d4f83583fc88a903d89d",
              "versionType": "git"
            },
            {
              "lessThan": "e40b7c44d19e327ad8b49a491ef1fa8dcc4566e0",
              "status": "affected",
              "version": "6001a930ce0378b62210d4f83583fc88a903d89d",
              "versionType": "git"
            },
            {
              "lessThan": "d4bc8271db21ea9f1c86a1ca4d64999f184d4aae",
              "status": "affected",
              "version": "6001a930ce0378b62210d4f83583fc88a903d89d",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/netfilter/nf_tables_api.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.12"
            },
            {
              "lessThan": "5.12",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.78",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.0.*",
              "status": "unaffected",
              "version": "6.0.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.78",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.0.8",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: netlink notifier might race to release objects\n\ncommit release path is invoked via call_rcu and it runs lockless to\nrelease the objects after rcu grace period. The netlink notifier handler\nmight win race to remove objects that the transaction context is still\nreferencing from the commit release path.\n\nCall rcu_barrier() to ensure pending rcu callbacks run to completion\nif the list of transactions to be destroyed is not empty."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The bug is reached via NETLINK_NETFILTER/nftables syscalls (create an owned table, commit deletions, then close the socket to fire NETLINK_URELEASE). This is a local netlink path, not packet-triggered remote code.\nAC:L - The attacker controls both sides of the race: committing nftables deletions that schedule async destroy work, then closing the owned netlink socket to trigger nft_rcv_nl_event. No external timing or victim state is required.\nPR:L - nfnetlink only requires CAP_NET_ADMIN via netlink_net_capable() in the network namespace\u2019s user_ns, which an unprivileged user obtains with user+net namespaces. NFT_TABLE_F_OWNER setup is reachable without real root.\nUI:N - Exploitation needs only the attacker\u2019s own netlink operations and socket close; no other user action is required.\nS:U - Impact is confined to the local kernel (standard nftables UAF/privilege escalation). It does not cross a VM, IOMMU, or other security-authority boundary.\nC:H - Syzbot confirms a KASAN use-after-free in nft_commit_release/nf_tables_trans_destroy_work after __nft_release_table frees objects still referenced by pending transactions; UAF of heap objects enables arbitrary read primitives.\nI:H - The same double-free/UAF of nftables chains/rules/sets is heap-controllable and can be turned into arbitrary write or control-flow hijacking, consistent with other exploitable nf_tables UAFs.\nA:H - The UAF reliably causes kernel oops/panic (observed KASAN crash in destroy work), so availability impact is high even without a full exploit."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T08:56:41.698Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1ffe7100411a8b9015115ce124cd6c9c9da6f8e3"
        },
        {
          "url": "https://git.kernel.org/stable/c/e40b7c44d19e327ad8b49a491ef1fa8dcc4566e0"
        },
        {
          "url": "https://git.kernel.org/stable/c/d4bc8271db21ea9f1c86a1ca4d64999f184d4aae"
        }
      ],
      "title": "netfilter: nf_tables: netlink notifier might race to release objects",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2022-49920",
    "datePublished": "2025-05-01T14:10:59.436Z",
    "dateReserved": "2025-05-01T14:05:17.252Z",
    "dateUpdated": "2026-08-05T08:56:41.698Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 4.7, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H\", \"integrityImpact\": \"NONE\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"HIGH\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"NONE\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2022-49920\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-10-01T14:58:43.450275Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-362\", \"description\": \"CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-10-01T14:19:13.590Z\"}}], \"cna\": {\"title\": \"netfilter: nf_tables: netlink notifier might race to release objects\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The bug is reached via NETLINK_NETFILTER/nftables syscalls (create an owned table, commit deletions, then close the socket to fire NETLINK_URELEASE). This is a local netlink path, not packet-triggered remote code.\\nAC:L - The attacker controls both sides of the race: committing nftables deletions that schedule async destroy work, then closing the owned netlink socket to trigger nft_rcv_nl_event. No external timing or victim state is required.\\nPR:L - nfnetlink only requires CAP_NET_ADMIN via netlink_net_capable() in the network namespace\\u2019s user_ns, which an unprivileged user obtains with user+net namespaces. NFT_TABLE_F_OWNER setup is reachable without real root.\\nUI:N - Exploitation needs only the attacker\\u2019s own netlink operations and socket close; no other user action is required.\\nS:U - Impact is confined to the local kernel (standard nftables UAF/privilege escalation). It does not cross a VM, IOMMU, or other security-authority boundary.\\nC:H - Syzbot confirms a KASAN use-after-free in nft_commit_release/nf_tables_trans_destroy_work after __nft_release_table frees objects still referenced by pending transactions; UAF of heap objects enables arbitrary read primitives.\\nI:H - The same double-free/UAF of nftables chains/rules/sets is heap-controllable and can be turned into arbitrary write or control-flow hijacking, consistent with other exploitable nf_tables UAFs.\\nA:H - The UAF reliably causes kernel oops/panic (observed KASAN crash in destroy work), so availability impact is high even without a full exploit.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6001a930ce0378b62210d4f83583fc88a903d89d\", \"lessThan\": \"1ffe7100411a8b9015115ce124cd6c9c9da6f8e3\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6001a930ce0378b62210d4f83583fc88a903d89d\", \"lessThan\": \"e40b7c44d19e327ad8b49a491ef1fa8dcc4566e0\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6001a930ce0378b62210d4f83583fc88a903d89d\", \"lessThan\": \"d4bc8271db21ea9f1c86a1ca4d64999f184d4aae\", \"versionType\": \"git\"}], \"programFiles\": [\"net/netfilter/nf_tables_api.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.12\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.12\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.15.78\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.0.8\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.0.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"net/netfilter/nf_tables_api.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/1ffe7100411a8b9015115ce124cd6c9c9da6f8e3\"}, {\"url\": \"https://git.kernel.org/stable/c/e40b7c44d19e327ad8b49a491ef1fa8dcc4566e0\"}, {\"url\": \"https://git.kernel.org/stable/c/d4bc8271db21ea9f1c86a1ca4d64999f184d4aae\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nnetfilter: nf_tables: netlink notifier might race to release objects\\n\\ncommit release path is invoked via call_rcu and it runs lockless to\\nrelease the objects after rcu grace period. The netlink notifier handler\\nmight win race to remove objects that the transaction context is still\\nreferencing from the commit release path.\\n\\nCall rcu_barrier() to ensure pending rcu callbacks run to completion\\nif the list of transactions to be destroyed is not empty.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.78\", \"versionStartIncluding\": \"5.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.0.8\", \"versionStartIncluding\": \"5.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1\", \"versionStartIncluding\": \"5.12\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T08:56:41.698Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2022-49920\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T08:56:41.698Z\", \"dateReserved\": \"2025-05-01T14:05:17.252Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2025-05-01T14:10:59.436Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…