Lucene search

K
vulnrichmentLinuxVULNRICHMENT:CVE-2022-48933
HistoryAug 22, 2024 - 3:31 a.m.

CVE-2022-48933 netfilter: nf_tables: fix memory leak during stateful obj update

2024-08-2203:31:27
Linux
github.com
1
linux kernel
netfilter
nf_tables
memory leak
stateful objects
module refcount

AI Score

6.9

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: fix memory leak during stateful obj update

stateful objects can be updated from the control plane.
The transaction logic allocates a temporary object for this purpose.

The ->init function was called for this object, so plain kfree() leaks
resources. We must call ->destroy function of the object.

nft_obj_destroy does this, but it also decrements the module refcount,
but the update path doesn’t increment it.

To avoid special-casing the update object release, do module_get for
the update case too and release it via nft_obj_destroy().

AI Score

6.9

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial