CVE-2022-50000 is a Linux kernel Netfilter flowtable cleanup flaw that can trigger a use-after-free when hardware-offload statistics or flow-add work remains pending during flowtable teardown. The race can defer hardware deletion work until after the flowtable has been freed, allowing the flow-offload work handler to access freed memory. The affected code was introduced in Linux kernel 5.5; upstream fixes are available in 5.15.64, 5.19.6, and 6.0 and later stable releases.
The fix flushes outstanding work before teardown, marks flows for removal, forces garbage-collection passes to queue and complete hardware flow-deletion work, and removes software flowtable entries only afterward. Red Hat rates the issue Moderate with CVSS v3 7.0 and lists fixes for affected RHEL 8 packages, including RHEL 8.4 Advanced Mission Critical Update Support and the 8.4 Extended Update Support Long-Life Add-On through RHSA-2025:15660; organizations should deploy current vendor-supported kernel updates rather than cherry-picking the patch.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Greg Kroah-Hartman published the Linux kernel CVE announcement describing a netfilter flowtable use-after-free caused by pending hardware offload work and recommending updates to current stable kernel releases.
Red Hat released RHSA-2023:0101 with fixed RHEL 8 kernel packages for CVE-2022-50000.
Red Hat listed the vulnerable code as absent from RHEL 9 in RHSA-2022:8267.
RHSA-2025:15660 addressed CVE-2022-50000 for RHEL 8.4 Advanced Mission Critical Update Support and RHEL 8.4 Extended Update Support Long-Life Add-On.
Red Hat made its CVE record for the netfilter flowtable cleanup vulnerability public, rating it Moderate with a CVSS v3 score of 7.0.
RHSA-2023:2951 delivered additional fixed RHEL 8 kernel packages for the vulnerability.
Red Hat issued RHSA-2023:0512, providing a kernel fix for RHEL 9.0 Extended Update Support.
The issue was fixed in Linux kernel versions 5.15.64, 5.19.6, and 6.0. The changes flush pending offload work, queue and flush hardware-removal work, and remove software flow entries before freeing the flowtable.
The vulnerable flowtable cleanup behavior was introduced in Linux kernel 5.5 by commit c29f74e0df7a02b8303bcdce93a7c0132d62577a.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.