Answer in brief
CVE-2022-48999 records a High severity (CVSS 7.1) vulnerability in ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=493ced1ac47c48bb86d9d4e8e87df8592be85a0e <cc3cd130ecfb8b0ae52e235e487bae3f16a24a32 || >=493ced1ac47c48bb86d9d4e8e87df8592be85a0e <0b5394229ebae09afc07aabccb5ffd705ffd250e || >=493ced1ac47c48bb86d9d4e8e87df8592be85a0e <25174d91e4a32a24204060d283bd5fa6d0ddf133 || >=493ced1ac47c48bb86d9d4e8e87df8592be85a0e <bb20a2ae241be846bc3c11ea4b3a3c69e41d51f2 || >=493ced1ac47c48bb86d9d4e8e87df8592be85a0e <61b91eb33a69c3be11b259c5ea484505cd79f883 | cc3cd130ecfb8b0ae52e235e487bae3f16a24a32, 0b5394229ebae09afc07aabccb5ffd705ffd250e, 25174d91e4a32a24204060d283bd5fa6d0ddf133, bb20a2ae241be846bc3c11ea4b3a3c69e41d51f2, 61b91eb33a69c3be11b259c5ea484505cd79f883 |
| Linux/Linuxgeneric | 5.3 | Not reported |
Published upstream
Oct 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference Gwangun Jung reported a slab-out-of-bounds access in fib_nh_match: fib_nh_match+0xf98/0x1130 linux-6.0-rc7/net/ipv4/fib_semantics.c:961 fib_table_delete+0x5f3/0xa40 linux-6.0-rc7/net/ipv4/fib_trie.c:1753 inet_rtm_delroute+0x2b3/0x380 linux-6.0-rc7/net/ipv4/fib_frontend.c:874 Separate nexthop objects are mutually exclusive with the legacy multipath spec. Fix fib_nh_match to return if the config for the to be deleted route contains a multipath spec while the fib_info is using a nexthop object.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2022-48999 records a High severity (CVSS 7.1) vulnerability in ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=493ced1ac47c48bb86d9d4e8e87df8592be85a0e <cc3cd130ecfb8b0ae52e235e487bae3f16a24a32 || >=493ced1ac47c48bb86d9d4e8e87df8592be85a0e <0b5394229ebae09afc07aabccb5ffd705ffd250e || >=493ced1ac47c48bb86d9d4e8e87df8592be85a0e <25174d91e4a32a24204060d283bd5fa6d0ddf133 || >=493ced1ac47c48bb86d9d4e8e87df8592be85a0e <bb20a2ae241be846bc3c11ea4b3a3c69e41d51f2 || >=493ced1ac47c48bb86d9d4e8e87df8592be85a0e <61b91eb33a69c3be11b259c5ea484505cd79f883 | cc3cd130ecfb8b0ae52e235e487bae3f16a24a32, 0b5394229ebae09afc07aabccb5ffd705ffd250e, 25174d91e4a32a24204060d283bd5fa6d0ddf133, bb20a2ae241be846bc3c11ea4b3a3c69e41d51f2, 61b91eb33a69c3be11b259c5ea484505cd79f883 |
| Linux/Linuxgeneric | 5.3 | Not reported |
Published upstream
Oct 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference Gwangun Jung reported a slab-out-of-bounds access in fib_nh_match: fib_nh_match+0xf98/0x1130 linux-6.0-rc7/net/ipv4/fib_semantics.c:961 fib_table_delete+0x5f3/0xa40 linux-6.0-rc7/net/ipv4/fib_trie.c:1753 inet_rtm_delroute+0x2b3/0x380 linux-6.0-rc7/net/ipv4/fib_frontend.c:874 Separate nexthop objects are mutually exclusive with the legacy multipath spec. Fix fib_nh_match to return if the config for the to be deleted route contains a multipath spec while the fib_info is using a nexthop object.
Quoted source text, attributed separately from HOL analysis.