CVE-2022-49183: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix ref leak when switching zones When switching zones or network namespaces without doing a ct clear in between, it is now leaking a reference to the old ct entry. That's because tcf_ct_skb_nfct_cached() returns false and tcf_ct_flow_table_lookup() may simply overwrite it. The fix is to, as the ct entry is not reusable, free it already at tcf_ct_skb_nfct_cached().

Affected products

  • Linux Linux Kernel: from 5.10.103, before 5.11 (fixed in 5.11); from 5.15.26, before 5.15.33 (fixed in 5.15.33); from 5.16.12, up to and including 5.16.19; from 5.17, up to and including 5.17.2

Published 2025-02-26. Last modified 2026-06-17.