cbcvebase.
CVE-2022-49589
published 2025-02-26

CVE-2022-49589: In the Linux kernel, the following vulnerability has been resolved: igmp: Fix data-races around sysctl_igmp_qrv. While reading sysctl_igmp_qrv, it can be…

PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: igmp: Fix data-races around sysctl_igmp_qrv. While reading sysctl_igmp_qrv, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers. This test can be packed into a helper, so such changes will be in the follow-up series after net is merged into net-next. qrv ?: READ_ONCE(net->ipv4.sysctl_igmp_qrv);

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.16-1 (bookworm)linux 5.18.16-1 (bookworm)
linuxlinux
linuxlinux>= a9fe8e29945d56f35235a3a0fba99b4cf181d211 < 9eeb3a7702998bdccbfcc37997b5dd9215b9a7f79eeb3a7702998bdccbfcc37997b5dd9215b9a7f7
linuxlinux>= a9fe8e29945d56f35235a3a0fba99b4cf181d211 < e20dd1b0e0ea15bee1e528536a0840dba972ca0ee20dd1b0e0ea15bee1e528536a0840dba972ca0e
linuxlinux>= a9fe8e29945d56f35235a3a0fba99b4cf181d211 < b399ffafffba39f47b731b26a5da1dc0ffc4b3adb399ffafffba39f47b731b26a5da1dc0ffc4b3ad
linuxlinux>= a9fe8e29945d56f35235a3a0fba99b4cf181d211 < c721324afc589f8ea54bae04756b150aeaae5fa4c721324afc589f8ea54bae04756b150aeaae5fa4
linuxlinux>= a9fe8e29945d56f35235a3a0fba99b4cf181d211 < c2954671010cd1127d1ffa328c6e6f8e99930982c2954671010cd1127d1ffa328c6e6f8e99930982
linuxlinux>= a9fe8e29945d56f35235a3a0fba99b4cf181d211 < 8ebcc62c738f68688ee7c6fec2efe5bc6d3d7e608ebcc62c738f68688ee7c6fec2efe5bc6d3d7e60
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 3.18 < 4.19.2554.19.255
linuxlinux_kernel>= 4.20 < 5.4.2095.4.209
linuxlinux_kernel>= 5.11 < 5.15.595.15.59
linuxlinux_kernel>= 5.16 < 5.18.155.18.15
linuxlinux_kernel>= 5.5 < 5.10.1355.10.135

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.