Answer in brief
CVE-2022-49110 records a High severity (CVSS 7.5) vulnerability in netfilter: conntrack: revisit gc autotuning. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4608fdfc07e116f9fc0895beb40abad7cdb5ee3d <58d52743ae85d28c9335c6034d6ce350b8689951 || >=4608fdfc07e116f9fc0895beb40abad7cdb5ee3d <7cd361d5e6d986c0d4cafb9ceaa803359048ae15 || >=4608fdfc07e116f9fc0895beb40abad7cdb5ee3d <592e57591826f3d09c28d755a39ea8e9d13705ad || >=4608fdfc07e116f9fc0895beb40abad7cdb5ee3d <2cfadb761d3d0219412fd8150faea60c7e863833 || dafc95a1e473a0b857af34ecbb17b8b1c90edd75 || 5892f910f401c1facfc410e0b042108f2827a77b || f68ad168e23565ce2a3891fec537cfaf8410d1e6 || 7aa03980b21fdc7355e20274a68a69a0b2a45c08 || >=4.19.206 <4.20 || >=5.4.144 <5.5 || >=5.10.62 <5.11 || >=5.13.14 <5.14 | 58d52743ae85d28c9335c6034d6ce350b8689951, 7cd361d5e6d986c0d4cafb9ceaa803359048ae15, 592e57591826f3d09c28d755a39ea8e9d13705ad, 2cfadb761d3d0219412fd8150faea60c7e863833, 4.20, 5.5, 5.11, 5.14 |
| Linux/Linuxgeneric | 5.14 | Not reported |
Published upstream
Feb 26, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: revisit gc autotuning as of commit 4608fdfc07e1 ("netfilter: conntrack: collect all entries in one cycle") conntrack gc was changed to run every 2 minutes. On systems where conntrack hash table is set to large value, most evictions happen from gc worker rather than the packet path due to hash table distribution. This causes netlink event overflows when events are collected. This change collects average expiry of scanned entries and reschedules to the average remaining value, within 1 to 60 second interval. To avoid event overflows, reschedule after each bucket and add a limit for both run time and number of evictions per run. If more entries have to be evicted, reschedule and restart 1 jiffy into the future.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2022-49110 records a High severity (CVSS 7.5) vulnerability in netfilter: conntrack: revisit gc autotuning. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4608fdfc07e116f9fc0895beb40abad7cdb5ee3d <58d52743ae85d28c9335c6034d6ce350b8689951 || >=4608fdfc07e116f9fc0895beb40abad7cdb5ee3d <7cd361d5e6d986c0d4cafb9ceaa803359048ae15 || >=4608fdfc07e116f9fc0895beb40abad7cdb5ee3d <592e57591826f3d09c28d755a39ea8e9d13705ad || >=4608fdfc07e116f9fc0895beb40abad7cdb5ee3d <2cfadb761d3d0219412fd8150faea60c7e863833 || dafc95a1e473a0b857af34ecbb17b8b1c90edd75 || 5892f910f401c1facfc410e0b042108f2827a77b || f68ad168e23565ce2a3891fec537cfaf8410d1e6 || 7aa03980b21fdc7355e20274a68a69a0b2a45c08 || >=4.19.206 <4.20 || >=5.4.144 <5.5 || >=5.10.62 <5.11 || >=5.13.14 <5.14 | 58d52743ae85d28c9335c6034d6ce350b8689951, 7cd361d5e6d986c0d4cafb9ceaa803359048ae15, 592e57591826f3d09c28d755a39ea8e9d13705ad, 2cfadb761d3d0219412fd8150faea60c7e863833, 4.20, 5.5, 5.11, 5.14 |
| Linux/Linuxgeneric | 5.14 | Not reported |
Published upstream
Feb 26, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: revisit gc autotuning as of commit 4608fdfc07e1 ("netfilter: conntrack: collect all entries in one cycle") conntrack gc was changed to run every 2 minutes. On systems where conntrack hash table is set to large value, most evictions happen from gc worker rather than the packet path due to hash table distribution. This causes netlink event overflows when events are collected. This change collects average expiry of scanned entries and reschedules to the average remaining value, within 1 to 60 second interval. To avoid event overflows, reschedule after each bucket and add a limit for both run time and number of evictions per run. If more entries have to be evicted, reschedule and restart 1 jiffy into the future.
Quoted source text, attributed separately from HOL analysis.