cbcvebase.
CVE-2022-49629
published 2025-02-26

CVE-2022-49629: In the Linux kernel, the following vulnerability has been resolved: nexthop: Fix data-races around nexthop_compat_mode. While reading nexthop_compat_mode, it…

PriorityP414medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: nexthop: Fix data-races around nexthop_compat_mode. While reading nexthop_compat_mode, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 4f80116d3df3b23ee4b83ea8557629e1799bc230 < a51040d4b120f3520df64fb0b9c63b31d69bea9ba51040d4b120f3520df64fb0b9c63b31d69bea9b
linuxlinux>= 4f80116d3df3b23ee4b83ea8557629e1799bc230 < 0d17723afea3ae8c9f245c9bbd2ba5945b77e8120d17723afea3ae8c9f245c9bbd2ba5945b77e812
linuxlinux>= 4f80116d3df3b23ee4b83ea8557629e1799bc230 < ae3054f6fbccc90f14ecd6cf9b2c09a2401c64fdae3054f6fbccc90f14ecd6cf9b2c09a2401c64fd
linuxlinux>= 4f80116d3df3b23ee4b83ea8557629e1799bc230 < bdf00bf24bef9be1ca641a6390fd5487873e0d2ebdf00bf24bef9be1ca641a6390fd5487873e0d2e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 5.11 < 5.15.565.15.56
linuxlinux_kernel>= 5.16 < 5.18.135.18.13
linuxlinux_kernel>= 5.8 < 5.10.1325.10.132

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.