cbcvebase.
CVE-2022-49587
published 2025-02-26

CVE-2022-49587: In the Linux kernel, the following vulnerability has been resolved: tcp: Fix a data-race around sysctl_tcp_notsent_lowat. While reading…

PriorityP414medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: tcp: Fix a data-race around sysctl_tcp_notsent_lowat. While reading sysctl_tcp_notsent_lowat, it can be changed concurrently. Thus, we need to add READ_ONCE() to its reader.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.16-1 (bookworm)linux 5.18.16-1 (bookworm)
linuxlinux
linuxlinux>= c9bee3b7fdecb0c1d070c7b54113b3bdfb9a3d36 < 91e21df688f8a75255ca9c459da39ac96300113a91e21df688f8a75255ca9c459da39ac96300113a
linuxlinux>= c9bee3b7fdecb0c1d070c7b54113b3bdfb9a3d36 < c1b85c5a34294f7444c13bf828e0e84b0a0eed85c1b85c5a34294f7444c13bf828e0e84b0a0eed85
linuxlinux>= c9bee3b7fdecb0c1d070c7b54113b3bdfb9a3d36 < 0f75343584ee474303e17efe0610bdd170af1d130f75343584ee474303e17efe0610bdd170af1d13
linuxlinux>= c9bee3b7fdecb0c1d070c7b54113b3bdfb9a3d36 < e9362a993886613ef0284c2a4911c6017c97d803e9362a993886613ef0284c2a4911c6017c97d803
linuxlinux>= c9bee3b7fdecb0c1d070c7b54113b3bdfb9a3d36 < fd6f1284e380c377932186042ff0b5c987fb2b92fd6f1284e380c377932186042ff0b5c987fb2b92
linuxlinux>= c9bee3b7fdecb0c1d070c7b54113b3bdfb9a3d36 < 80d4d0c461674eea87f0977e12a2ecd334b9b79c80d4d0c461674eea87f0977e12a2ecd334b9b79c
linuxlinux>= c9bee3b7fdecb0c1d070c7b54113b3bdfb9a3d36 < 62e56cfeb2ae4b53ae9ca24c80f54093250ce64a62e56cfeb2ae4b53ae9ca24c80f54093250ce64a
linuxlinux>= c9bee3b7fdecb0c1d070c7b54113b3bdfb9a3d36 < 55be873695ed8912eb77ff46d1d1cadf028bd0f355be873695ed8912eb77ff46d1d1cadf028bd0f3
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 3.12 < 4.9.3254.9.325
linuxlinux_kernel>= 4.10 < 4.14.2904.14.290
linuxlinux_kernel>= 4.15 < 4.19.2544.19.254
linuxlinux_kernel>= 4.20 < 5.4.2085.4.208
linuxlinux_kernel>= 5.11 < 5.15.585.15.58
linuxlinux_kernel>= 5.16 < 5.18.155.18.15
linuxlinux_kernel>= 5.5 < 5.10.1345.10.134

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.