CVE-2022-49183 is a reference leak vulnerability in the Linux kernel's networking subsystem (net/sched: act_ct). Specifically, it occurs when switching network zones or namespaces without clearing connection tracking entries, leading to a leaked reference to the old entry. This vulnerability affects the Linux kernel. Rated as Medium severity with a CVSS score of 5.5, this local vulnerability (AV:L) has low attack complexity (AC:L) and requires low privileges (PR:L). While it doesn't impact confidentiality or integrity (C:N/I:N), it can lead to high availability impact (A:H), potentially causing system instability or denial of service. There is currently no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10.103, < 5.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.15.26, < 5.15.33CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16.12, <= 5.16.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.17, <= 5.17.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.10.103, < 5.10.258CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.