CVE-2022-49921: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: sched: Fix use after free in red_enqueue() We can't use "skb" again after passing it to qdisc_enqueue(). This is basically identical to commit 2f09707d0c97 ("sch_sfb: Also store skb len before calling child enqueue").

Affected products

  • Linux Linux Kernel: from 4.4.163, before 4.5 (fixed in 4.5); from 4.7, before 4.9.333 (fixed in 4.9.333); from 4.10, before 4.14.299 (fixed in 4.14.299); from 4.15, before 4.19.265 (fixed in 4.19.265); from 4.20, before 5.4.224 (fixed in 5.4.224); from 5.5, before 5.10.154 (fixed in 5.10.154); …

Published 2025-05-01. Last modified 2026-06-17.