cbcvebase.
CVE-2022-49596
published 2025-02-26

CVE-2022-49596: In the Linux kernel, the following vulnerability has been resolved: tcp: Fix data-races around sysctl_tcp_min_snd_mss. While reading sysctl_tcp_min_snd_mss, it…

PriorityP414medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.18%
8.4th percentile
In the Linux kernel, the following vulnerability has been resolved: tcp: Fix data-races around sysctl_tcp_min_snd_mss. While reading sysctl_tcp_min_snd_mss, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.16-1 (bookworm)linux 5.18.16-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.16.69 < 3.173.17
linuxlinux>= 4.14.127 < 4.154.15
linuxlinux>= 4.19.52 < 4.204.20
linuxlinux>= 4.4.182 < 4.54.5
linuxlinux>= 4.9.182 < 4.104.10
linuxlinux>= 5.1.11 < 5.25.2
linuxlinux>= 5f3e2bf008c2221478101ee72f5cb4654b9fc363 < fdb96b69f5909ffcdd6f1e0902219fc6d7689ff7fdb96b69f5909ffcdd6f1e0902219fc6d7689ff7
linuxlinux>= 5f3e2bf008c2221478101ee72f5cb4654b9fc363 < 97992e8feff33b3ae154a113ec398546bbacda8097992e8feff33b3ae154a113ec398546bbacda80
linuxlinux>= 5f3e2bf008c2221478101ee72f5cb4654b9fc363 < 0fc9357282df055e30990b29f4b7afa53ab42cdb0fc9357282df055e30990b29f4b7afa53ab42cdb
linuxlinux>= 5f3e2bf008c2221478101ee72f5cb4654b9fc363 < 0d8a39feb58910a7f7746b1770ee5578cc551fe60d8a39feb58910a7f7746b1770ee5578cc551fe6
linuxlinux>= 5f3e2bf008c2221478101ee72f5cb4654b9fc363 < 78eb166cdefcc3221c8c7c1e2d514e91a2eb501478eb166cdefcc3221c8c7c1e2d514e91a2eb5014
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 3.16.69 < 3.173.17

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.