CVE-2022-1678
published 2022-05-25CVE-2022-1678: An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.91%
85.4th percentile
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.2.6-1 (bookworm) | linux 5.2.6-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 4.18 < unspecified | unspecified |
| linux | linux_kernel | 4.18 – 4.19 | — |
| linux | linux_kernel | unspecified – 4.19 | — |
| netapp | e-series_santricity_os_controller | 11.0 – 11.70.2 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: improper update of sock reference in TCP pacing can lead to memory leak
vendor_redhat·2022-05-20·CVSS 5.9
CVE-2022-1678 [MEDIUM] CWE-911 kernel: improper update of sock reference in TCP pacing can lead to memory leak
kernel: improper update of sock reference in TCP pacing can lead to memory leak
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.
A flaw was found in the Linux kernel. An incorrect update of the sock reference in TCP pacing can lead to a memory leak, wasting memory on the system.
Mitigation: Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Packa
Debian
CVE-2022-1678: linux - An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper updat...
vendor_debian·2022·CVSS 5.9
CVE-2022-1678 [MEDIUM] CVE-2022-1678: linux - An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper updat...
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed in 5.2.6-1)
GHSA
GHSA-x4fc-h5x4-26gr: An issue was discovered in the Linux Kernel from 4
ghsa_unreviewed·2022-05-26
CVE-2022-1678 [HIGH] GHSA-x4fc-h5x4-26gr: An issue was discovered in the Linux Kernel from 4
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.
OSV
CVE-2022-1678: An issue was discovered in the Linux Kernel from 4
osv·2022-05-25·CVSS 7.5
CVE-2022-1678 [HIGH] CVE-2022-1678: An issue was discovered in the Linux Kernel from 4
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-1678 kernel: improper update of sock reference in TCP pacing can lead to memory leak
bugzilla·2022-05-30·CVSS 7.5
CVE-2022-1678 [HIGH] CVE-2022-1678 kernel: improper update of sock reference in TCP pacing can lead to memory leak
CVE-2022-1678 kernel: improper update of sock reference in TCP pacing can lead to memory leak
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.
References:
https://gitee.com/anolis/cloud-kernel/commit/bed537da691b
https://bugzilla.openanolis.cn/show_bug.cgi?id=61
https://lore.kernel.org/all/[email protected]/
https://github.com/torvalds/linux/commit/0a70f118475e037732557796accd0878a00fc25a
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2091705]
---
This was fixed for Fedora years ago in the 4.20 kernel rebases.
---
RHEL 8 based products are not marked as affected, this was fixed in 8.4
Checkpoint
25th January – Threat Intelligence Report
blogs_checkpoint·2021-01-25
CVE-2021-1678 25th January – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 25th January – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 25th January, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The CHwapi hospital in Belgium has been hit by BitLocker, encrypting 40 of its servers and 100 TB of data. The attack caused the hospital to redirect patients and delay surgical procedures.
Check Point SandBlast Agent provides protection against this threat
Cybersecurity firm SonicWall has suffered an attack on its inte
https://anas.openanolis.cn/cves/detail/CVE-2022-1678https://anas.openanolis.cn/errata/detail/ANSA-2022:0143https://bugzilla.openanolis.cn/show_bug.cgi?id=61https://gitee.com/anolis/cloud-kernel/commit/bed537da691bhttps://github.com/torvalds/linux/commit/0a70f118475e037732557796accd0878a00fc25ahttps://lore.kernel.org/all/20200602080425.93712-1-kerneljasonxing%40gmail.com/https://security.netapp.com/advisory/ntap-20220715-0001/https://anas.openanolis.cn/cves/detail/CVE-2022-1678https://anas.openanolis.cn/errata/detail/ANSA-2022:0143https://bugzilla.openanolis.cn/show_bug.cgi?id=61https://gitee.com/anolis/cloud-kernel/commit/bed537da691bhttps://github.com/torvalds/linux/commit/0a70f118475e037732557796accd0878a00fc25ahttps://lore.kernel.org/all/20200602080425.93712-1-kerneljasonxing%40gmail.com/https://security.netapp.com/advisory/ntap-20220715-0001/
2022-05-25
Published