cbcvebase.
CVE-2022-49577
published 2025-02-26

CVE-2022-49577: In the Linux kernel, the following vulnerability has been resolved: udp: Fix a data-race around sysctl_udp_l3mdev_accept. While reading…

PriorityP414medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.18%
8.4th percentile
In the Linux kernel, the following vulnerability has been resolved: udp: Fix a data-race around sysctl_udp_l3mdev_accept. While reading sysctl_udp_l3mdev_accept, it can be changed concurrently. Thus, we need to add READ_ONCE() to its reader.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.16-1 (bookworm)linux 5.18.16-1 (bookworm)
linuxlinux
linuxlinux>= 63a6fff353d01da5a22b72670c434bf12fa0e3b8 < f39b03bd727a8fea62e82f10fe2e0d753b9930fff39b03bd727a8fea62e82f10fe2e0d753b9930ff
linuxlinux>= 63a6fff353d01da5a22b72670c434bf12fa0e3b8 < fcaef69c79ec222e55643e666b80b221e70fa6a8fcaef69c79ec222e55643e666b80b221e70fa6a8
linuxlinux>= 63a6fff353d01da5a22b72670c434bf12fa0e3b8 < 3f2ac2d6511bb0652abf4d7388d65bb9ff1c641c3f2ac2d6511bb0652abf4d7388d65bb9ff1c641c
linuxlinux>= 63a6fff353d01da5a22b72670c434bf12fa0e3b8 < cb0d28934ca10f99c47e2c6f451405d6c954fe48cb0d28934ca10f99c47e2c6f451405d6c954fe48
linuxlinux>= 63a6fff353d01da5a22b72670c434bf12fa0e3b8 < 3d72bb4188c708bb16758c60822fc4dda7a951743d72bb4188c708bb16758c60822fc4dda7a95174
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 4.11 < 5.4.2085.4.208
linuxlinux_kernel>= 5.11 < 5.15.585.15.58
linuxlinux_kernel>= 5.16 < 5.18.155.18.15
linuxlinux_kernel>= 5.5 < 5.10.1345.10.134

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.