CVE-2022-49344
published 2025-02-26CVE-2022-49344: In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix a data-race in unix_dgram_peer_wake_me(). unix_dgram_poll() calls…
PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.19%
8.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
af_unix: Fix a data-race in unix_dgram_peer_wake_me().
unix_dgram_poll() calls unix_dgram_peer_wake_me() without `other`'s
lock held and check if its receive queue is full. Here we need to
use unix_recvq_full_lockless() instead of unix_recvq_full(), otherwise
KCSAN will report a data-race.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.5-1 (bookworm) | linux 5.18.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 2.6.32.70 < 2.6.33 | 2.6.33 |
| linux | linux | >= 3.10.95 < 3.11 | 3.11 |
| linux | linux | >= 3.12.52 < 3.13 | 3.13 |
| linux | linux | >= 3.14.59 < 3.15 | 3.15 |
| linux | linux | >= 3.18.26 < 3.19 | 3.19 |
| linux | linux | >= 3.2.75 < 3.3 | 3.3 |
| linux | linux | >= 3.4.111 < 3.5 | 3.5 |
| linux | linux | >= 4.1.15 < 4.2 | 4.2 |
| linux | linux | >= 4.2.8 < 4.3 | 4.3 |
| linux | linux | >= 4.3.3 < 4.4 | 4.4 |
| linux | linux | >= 7d267278a9ece963d77eefec61630223fce08c6c < 95f0ba806277733bf6024e23e27e1be773701cca | 95f0ba806277733bf6024e23e27e1be773701cca |
| linux | linux | >= 7d267278a9ece963d77eefec61630223fce08c6c < 556720013c36c193d9cbfb06e7b33e51f0c39fbf | 556720013c36c193d9cbfb06e7b33e51f0c39fbf |
| linux | linux | >= 7d267278a9ece963d77eefec61630223fce08c6c < c61848500a3fd6867dfa4834b8c7f97133eceb9f | c61848500a3fd6867dfa4834b8c7f97133eceb9f |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j4wc-x6gv-2p4c: In the Linux kernel, the following vulnerability has been resolved:
af_unix: Fix a data-race in unix_dgram_peer_wake_me()
ghsa_unreviewed·2025-03-14
CVE-2022-49344 [MEDIUM] CWE-362 GHSA-j4wc-x6gv-2p4c: In the Linux kernel, the following vulnerability has been resolved:
af_unix: Fix a data-race in unix_dgram_peer_wake_me()
In the Linux kernel, the following vulnerability has been resolved:
af_unix: Fix a data-race in unix_dgram_peer_wake_me().
unix_dgram_poll() calls unix_dgram_peer_wake_me() without `other`'s
lock held and check if its receive queue is full. Here we need to
use unix_recvq_full_lockless() instead of unix_recvq_full(), otherwise
KCSAN will report a data-race.
OSV
CVE-2022-49344: In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix a data-race in unix_dgram_peer_wake_me()
osv·2025-02-26·CVSS 4.7
CVE-2022-49344 [MEDIUM] CVE-2022-49344: In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix a data-race in unix_dgram_peer_wake_me()
In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix a data-race in unix_dgram_peer_wake_me(). unix_dgram_poll() calls unix_dgram_peer_wake_me() without `other`'s lock held and check if its receive queue is full. Here we need to use unix_recvq_full_lockless() instead of unix_recvq_full(), otherwise KCSAN will report a data-race.
Red Hat
kernel: af_unix: Fix a data-race in unix_dgram_peer_wake_me().
vendor_redhat·2025-02-26·CVSS 4.7
CVE-2022-49344 [MEDIUM] CWE-362 kernel: af_unix: Fix a data-race in unix_dgram_peer_wake_me().
kernel: af_unix: Fix a data-race in unix_dgram_peer_wake_me().
In the Linux kernel, the following vulnerability has been resolved:
af_unix: Fix a data-race in unix_dgram_peer_wake_me().
unix_dgram_poll() calls unix_dgram_peer_wake_me() without `other`'s
lock held and check if its receive queue is full. Here we need to
use unix_recvq_full_lockless() instead of unix_recvq_full(), otherwise
KCSAN will report a data-race.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Out of support scope
Package: kernel-rt (Red Hat Enterpr
Debian
CVE-2022-49344: linux - In the Linux kernel, the following vulnerability has been resolved: af_unix: Fi...
vendor_debian·2022·CVSS 4.7
CVE-2022-49344 [MEDIUM] CVE-2022-49344: linux - In the Linux kernel, the following vulnerability has been resolved: af_unix: Fi...
In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix a data-race in unix_dgram_peer_wake_me(). unix_dgram_poll() calls unix_dgram_peer_wake_me() without `other`'s lock held and check if its receive queue is full. Here we need to use unix_recvq_full_lockless() instead of unix_recvq_full(), otherwise KCSAN will report a data-race.
Scope: local
bookworm: resolved (fixed in 5.18.5-1)
bullseye: resolved (fixed in 5.10.127-1)
forky: resolved (fixed in 5.18.5-1)
sid: resolved (fixed in 5.18.5-1)
trixie: resolved (fixed in 5.18.5-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/556720013c36c193d9cbfb06e7b33e51f0c39fbfhttps://git.kernel.org/stable/c/662a80946ce13633ae90a55379f1346c10f0c432https://git.kernel.org/stable/c/71e8bfc7f838cabc60cba24e09ca84c4f8321ab2https://git.kernel.org/stable/c/8801eb3ccd2e4e3b1a01449383e3321ae6dbd9d6https://git.kernel.org/stable/c/95f0ba806277733bf6024e23e27e1be773701ccahttps://git.kernel.org/stable/c/c61848500a3fd6867dfa4834b8c7f97133eceb9fhttps://git.kernel.org/stable/c/c926ae58f24f7bd55aa2ea4add9f952032507913
2025-02-26
Published