MEDIUM
netfilter: nf_tables: initialize registers in nft_do_chain()
Published Feb 26, 2025
6.1
MEDIUMCVSS 3.1
EPSS 0.29%
Description
Initialize registers to avoid stack leak into userspace.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.13StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.13
- Version 4.14.274StatusunaffectedConstraints<=4.14.*
- Version 4.19.237StatusunaffectedConstraints<=4.19.*
- Version 4.9.309StatusunaffectedConstraints<=4.9.*
- Version 5.10.109StatusunaffectedConstraints<=5.10.*
- Version 5.15.32StatusunaffectedConstraints<=5.15.*
- Version 5.16.18StatusunaffectedConstraints<=5.16.*
- Version 5.17.1StatusunaffectedConstraints<=5.17.*
- Version 5.18StatusunaffectedConstraints<=*
- Version 5.4.188StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
OR
- ≥ 3.13 · < 4.9.309
- ≥ 4.10 · < 4.14.274
- ≥ 4.15 · < 4.19.237
- ≥ 4.20 · < 5.4.188
- ≥ 5.5 · < 5.10.109
- ≥ 5.11 · < 5.15.32
- ≥ 5.16 · < 5.16.18
- 5.17
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (15)
- https://access.redhat.com/security/cve/CVE-2022-49293 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2347833 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-54933 Advisory
- https://git.kernel.org/stable/c/06f0ff82c70241a766a811ae1acf07d6e2734dcb Patch
- https://git.kernel.org/stable/c/2c74374c2e88c7b7992bf808d9f9391f7452f9d9 Patch
- https://git.kernel.org/stable/c/4c905f6740a365464e91467aa50916555b28213d Patch
- https://git.kernel.org/stable/c/4d28522acd1c4415c85f6b33463713a268f68965 Patch
- https://git.kernel.org/stable/c/64f24c76dd0ce53d0fa3a0bfb9aeea507c769485 Patch
- https://git.kernel.org/stable/c/88791b79a1eb2ba94e95d039243e28433583a67b Patch
- https://git.kernel.org/stable/c/a3cc32863b175168283cb0a5fde08de6a1e27df9 Patch
- https://git.kernel.org/stable/c/dd03640529204ef4b8189fbdea08217d8d98271f Patch
- https://git.kernel.org/stable/c/fafb904156fbb8f1dd34970cd5223e00b47c33be Patch
- https://lore.kernel.org/linux-cve-announce/2025022634-CVE-2022-49293-15b7@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49293
- https://www.cve.org/CVERecord?id=CVE-2022-49293
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Feb 26, 2025
Updated May 11, 2026
Reserved Feb 26, 2025
Link CVE-2022-49293
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-54933 Assigner Linux
Published Feb 26, 2025
Updated May 11, 2026
Exploited since n/a
Link EUVD-2022-54933