In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: release flow rule object from commit path
No need to postpone this to the commit release path, since no packets are walking over this object, this is accessed from control plane only. This helped uncovered UAF triggered by races with the netlink notifier.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49919.json",
"cna_assigner": "Linux"
}[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b2d7a92aff0fbd93c29d2aa6451fb99f050e2c4e",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "net/netfilter/nf_tables_api.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"46633852258639905358075294784093931905",
"302417611663088311207863897750291537074",
"270204712085626404298428580449485368950",
"204792596519896984439762140723952899643",
"172479189452375187718601225378629424850",
"172157329452680120210575229435713256921",
"315656042834679634545404781834347649318",
"70668269608038108213759751867093479733",
"206532656306368858196924568306931783442"
]
},
"signature_version": "v1",
"id": "CVE-2022-49919-04ca7584"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@74fd5839467054cd9c4d050614d3ee8788386171",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "net/netfilter/nf_tables_api.c",
"function": "nft_commit_release"
},
"digest": {
"length": 884.0,
"function_hash": "174336961563534038651587536003076139820"
},
"signature_version": "v1",
"id": "CVE-2022-49919-1a04bb9f"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@74fd5839467054cd9c4d050614d3ee8788386171",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "net/netfilter/nf_tables_api.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"46633852258639905358075294784093931905",
"302417611663088311207863897750291537074",
"270204712085626404298428580449485368950",
"204792596519896984439762140723952899643",
"172479189452375187718601225378629424850",
"172157329452680120210575229435713256921",
"315656042834679634545404781834347649318",
"70668269608038108213759751867093479733",
"206532656306368858196924568306931783442"
]
},
"signature_version": "v1",
"id": "CVE-2022-49919-2762bd4a"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b2d7a92aff0fbd93c29d2aa6451fb99f050e2c4e",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "net/netfilter/nf_tables_api.c",
"function": "nft_commit_release"
},
"digest": {
"length": 968.0,
"function_hash": "339280558904087326372547951911097977606"
},
"signature_version": "v1",
"id": "CVE-2022-49919-42cb85d4"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@26b5934ff4194e13196bedcba373cd4915071d0e",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "net/netfilter/nf_tables_api.c",
"function": "nft_commit_release"
},
"digest": {
"length": 968.0,
"function_hash": "339280558904087326372547951911097977606"
},
"signature_version": "v1",
"id": "CVE-2022-49919-50d5a56a"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@74fd5839467054cd9c4d050614d3ee8788386171",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "net/netfilter/nf_tables_api.c",
"function": "nf_tables_commit"
},
"digest": {
"length": 4083.0,
"function_hash": "284916976559564806935504127642408526718"
},
"signature_version": "v1",
"id": "CVE-2022-49919-59179330"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4ab6f96444e936f5e4a936d5c0bc948144bcded3",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "net/netfilter/nf_tables_api.c",
"function": "nf_tables_commit"
},
"digest": {
"length": 5070.0,
"function_hash": "44145049010191325515553994573311665332"
},
"signature_version": "v1",
"id": "CVE-2022-49919-78b29a7e"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4ab6f96444e936f5e4a936d5c0bc948144bcded3",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "net/netfilter/nf_tables_api.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"46633852258639905358075294784093931905",
"302417611663088311207863897750291537074",
"270204712085626404298428580449485368950",
"204792596519896984439762140723952899643",
"172479189452375187718601225378629424850",
"172157329452680120210575229435713256921",
"315656042834679634545404781834347649318",
"70668269608038108213759751867093479733",
"206532656306368858196924568306931783442"
]
},
"signature_version": "v1",
"id": "CVE-2022-49919-7eaa71a2"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@26b5934ff4194e13196bedcba373cd4915071d0e",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "net/netfilter/nf_tables_api.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"46633852258639905358075294784093931905",
"302417611663088311207863897750291537074",
"270204712085626404298428580449485368950",
"204792596519896984439762140723952899643",
"172479189452375187718601225378629424850",
"172157329452680120210575229435713256921",
"315656042834679634545404781834347649318",
"70668269608038108213759751867093479733",
"206532656306368858196924568306931783442"
]
},
"signature_version": "v1",
"id": "CVE-2022-49919-8427dc7e"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6044791b7be707fd0e709f26e961a446424e5051",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "net/netfilter/nf_tables_api.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"46633852258639905358075294784093931905",
"302417611663088311207863897750291537074",
"270204712085626404298428580449485368950",
"204792596519896984439762140723952899643",
"172479189452375187718601225378629424850",
"172157329452680120210575229435713256921",
"315656042834679634545404781834347649318",
"70668269608038108213759751867093479733",
"206532656306368858196924568306931783442"
]
},
"signature_version": "v1",
"id": "CVE-2022-49919-a40fdd75"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4ab6f96444e936f5e4a936d5c0bc948144bcded3",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "net/netfilter/nf_tables_api.c",
"function": "nft_commit_release"
},
"digest": {
"length": 968.0,
"function_hash": "339280558904087326372547951911097977606"
},
"signature_version": "v1",
"id": "CVE-2022-49919-aa074a92"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@26b5934ff4194e13196bedcba373cd4915071d0e",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "net/netfilter/nf_tables_api.c",
"function": "nf_tables_commit"
},
"digest": {
"length": 5070.0,
"function_hash": "44145049010191325515553994573311665332"
},
"signature_version": "v1",
"id": "CVE-2022-49919-affec77d"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6044791b7be707fd0e709f26e961a446424e5051",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "net/netfilter/nf_tables_api.c",
"function": "nf_tables_commit"
},
"digest": {
"length": 5070.0,
"function_hash": "44145049010191325515553994573311665332"
},
"signature_version": "v1",
"id": "CVE-2022-49919-b3d82ad9"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b2d7a92aff0fbd93c29d2aa6451fb99f050e2c4e",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "net/netfilter/nf_tables_api.c",
"function": "nf_tables_commit"
},
"digest": {
"length": 4898.0,
"function_hash": "318056263921916689161663609536064018614"
},
"signature_version": "v1",
"id": "CVE-2022-49919-d03c9c94"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6044791b7be707fd0e709f26e961a446424e5051",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "net/netfilter/nf_tables_api.c",
"function": "nft_commit_release"
},
"digest": {
"length": 968.0,
"function_hash": "339280558904087326372547951911097977606"
},
"signature_version": "v1",
"id": "CVE-2022-49919-d1989992"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49919.json"