CVE-2022-49698: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: netfilter: use get_random_u32 instead of prandom bh might occur while updating per-cpu rnd_state from user context, ie. local_out path. BUG: using smp_processor_id() in preemptible [00000000] code: nginx/2725 caller is nft_ng_random_eval+0x24/0x54 [nft_numgen] Call Trace: check_preemption_disabled+0xde/0xe0 nft_ng_random_eval+0x24/0x54 [nft_numgen] Use the random driver instead, this also avoids need for local prandom state. Moreover, prandom now uses the random driver since d4150779e60f ("random32: use real rng for non-deterministic randomness"). Based on earlier patch from Pablo Neira.
Affected products
- Linux Linux Kernel: from 4.18, before 5.10.127 (fixed in 5.10.127); from 5.11, before 5.15.51 (fixed in 5.15.51); from 5.16, before 5.18.8 (fixed in 5.18.8); version 5.19 only
Published 2025-02-26. Last modified 2026-06-17.