CVE-2022-48933 Details
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memory leak during stateful obj update stateful objects can be updated from the control plane. The transaction logic allocates a temporary object for this purpose. The ->init function was called for this object, so plain kfree() leaks resources. We must call ->destroy function of the object. nft_obj_destroy does this, but it also decrements the module refcount, but the update path doesn't increment it. To avoid special-casing the update object release, do module_get for the update case too and release it via nft_obj_destroy().
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 10, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/34bb90e407e3288f610558beaae54ecaa32b11c4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/53026346a94c43f35c32b18804041bc483271d87 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7e9880e81d3fd6a43c202f205717485290432826 | kernel.org | Patch |
| https://git.kernel.org/stable/c/dad3bdeef45f81a6e90204bcc85360bb76eccec7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e96e204ee6fa46702f6c94c3c69a09e69e0eac52 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.4, < 5.4.182 >= 5.5, < 5.10.103 >= 5.11, < 5.15.26 >= 5.16, < 5.16.12 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 23, 2024 | Initial Analysis | [email protected] |
| Aug 22, 2024 | New CVE Received | kernel.org |