CVE-2022-48757 is a Linux kernel networking information-disclosure flaw in /proc/net/ptype. A packet socket created without binding to a device in one network namespace could expose its associated packet_type entry to users reading that interface from another namespace, weakening expected namespace isolation. The defect existed since Linux kernel 2.6.26.
Upstream corrected the issue by associating each packet_type with its network namespace and filtering entries during ptype_seq_show; fixes were backported to kernels including 4.4.302, 4.9.300, 4.14.265, 4.19.228, 5.4.176, 5.10.96, 5.15.19, 5.16.5, and 5.17. Red Hat rates the issue Low with CVSS 3.3, has issued RHEL 8 and RHEL 8.8 EUS updates, and advises applying supported kernel updates; RHEL 9 fixes were deferred, while RHEL 6 and 7 are outside support scope.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:5101 for RHEL 8 kernel updates and RHSA-2024:5102 for RHEL 8 kernel-rt updates addressing CVE-2022-48757.
Red Hat reported its security record for CVE-2022-48757, a low-severity Linux kernel information-disclosure issue affecting /proc/net/ptype.
Red Hat issued RHSA-2024:6206, providing a kernel update for Red Hat Enterprise Linux 8.8 Extended Update Support that addresses CVE-2022-48757.
The Linux kernel remediation associated packet_type entries with their corresponding network namespace and made ptype_seq_show filter entries accordingly. The fix was backported through stable releases 4.4.302, 4.9.300, 4.14.265, 4.19.228, 5.4.176, 5.10.96, 5.15.19, 5.16.5, and 5.17.
The cross-network-namespace information-leak issue in /proc/net/ptype was introduced by commit 2feb27dbe00c in Linux kernel version 2.6.26.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.