cbcvebase.
CVE-2022-49344
published 2025-02-26

CVE-2022-49344: In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix a data-race in unix_dgram_peer_wake_me(). unix_dgram_poll() calls…

PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.19%
8.9th percentile
In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix a data-race in unix_dgram_peer_wake_me(). unix_dgram_poll() calls unix_dgram_peer_wake_me() without `other`'s lock held and check if its receive queue is full. Here we need to use unix_recvq_full_lockless() instead of unix_recvq_full(), otherwise KCSAN will report a data-race.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 2.6.32.70 < 2.6.332.6.33
linuxlinux>= 3.10.95 < 3.113.11
linuxlinux>= 3.12.52 < 3.133.13
linuxlinux>= 3.14.59 < 3.153.15
linuxlinux>= 3.18.26 < 3.193.19
linuxlinux>= 3.2.75 < 3.33.3
linuxlinux>= 3.4.111 < 3.53.5
linuxlinux>= 4.1.15 < 4.24.2
linuxlinux>= 4.2.8 < 4.34.3
linuxlinux>= 4.3.3 < 4.44.4
linuxlinux>= 7d267278a9ece963d77eefec61630223fce08c6c < 95f0ba806277733bf6024e23e27e1be773701cca95f0ba806277733bf6024e23e27e1be773701cca
linuxlinux>= 7d267278a9ece963d77eefec61630223fce08c6c < 556720013c36c193d9cbfb06e7b33e51f0c39fbf556720013c36c193d9cbfb06e7b33e51f0c39fbf
linuxlinux>= 7d267278a9ece963d77eefec61630223fce08c6c < c61848500a3fd6867dfa4834b8c7f97133eceb9fc61848500a3fd6867dfa4834b8c7f97133eceb9f

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.