๐Ÿ” CVE Alert

CVE-2022-49698

UNKNOWN 0.0

netfilter: use get_random_u32 instead of prandom

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: netfilter: use get_random_u32 instead of prandom bh might occur while updating per-cpu rnd_state from user context, ie. local_out path. BUG: using smp_processor_id() in preemptible [00000000] code: nginx/2725 caller is nft_ng_random_eval+0x24/0x54 [nft_numgen] Call Trace: check_preemption_disabled+0xde/0xe0 nft_ng_random_eval+0x24/0x54 [nft_numgen] Use the random driver instead, this also avoids need for local prandom state. Moreover, prandom now uses the random driver since d4150779e60f ("random32: use real rng for non-deterministic randomness"). Based on earlier patch from Pablo Neira.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Feb 26, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
978d8f9055c3a7c35db2ac99cd2580b993396e33 < 15cc30ac2a8d7185f8ebf97dd1ddd90a7c79783b 978d8f9055c3a7c35db2ac99cd2580b993396e33 < d0906b0fffc9f19bc42708ca3e84e2089088386c 978d8f9055c3a7c35db2ac99cd2580b993396e33 < 6ce71f83f798be7e1ca68707fec449fbecb38852 978d8f9055c3a7c35db2ac99cd2580b993396e33 < b1fd94e704571f98b21027340eecf821b2bdffba
Linux / Linux
4.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/15cc30ac2a8d7185f8ebf97dd1ddd90a7c79783b git.kernel.org: https://git.kernel.org/stable/c/d0906b0fffc9f19bc42708ca3e84e2089088386c git.kernel.org: https://git.kernel.org/stable/c/6ce71f83f798be7e1ca68707fec449fbecb38852 git.kernel.org: https://git.kernel.org/stable/c/b1fd94e704571f98b21027340eecf821b2bdffba