CVE-2022-48643: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix nft_counters_enabled underflow at nf_tables_addchain() syzbot is reporting underflow of nft_counters_enabled counter at nf_tables_addchain() [1], for commit 43eb8949cfdffa76 ("netfilter: nf_tables: do not leave chain stats enabled on error") missed that nf_tables_chain_destroy() after nft_basechain_init() in the error path of nf_tables_addchain() decrements the counter because nft_basechain_init() makes nft_is_base_chain() return true by setting NFT_CHAIN_BASE flag. Increment the counter immediately after returning from nft_basechain_init().

Affected products

  • Linux Linux Kernel: from 5.10.140, before 5.10.146 (fixed in 5.10.146); from 5.15.64, before 5.15.71 (fixed in 5.15.71); from 5.19.6, before 5.19.12 (fixed in 5.19.12); version 6.0 only

Published 2024-04-28. Last modified 2026-06-17.