cbcvebase.
CVE-2022-49639
published 2025-02-26

CVE-2022-49639: In the Linux kernel, the following vulnerability has been resolved: cipso: Fix data-races around sysctl. While reading cipso sysctl variables, they can be…

PriorityP414medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.18%
7.2th percentile
In the Linux kernel, the following vulnerability has been resolved: cipso: Fix data-races around sysctl. While reading cipso sysctl variables, they can be changed concurrently. So, we need to add READ_ONCE() to avoid data-races.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < 2764f82bbc158d106693ae3ced3675cf4b963b352764f82bbc158d106693ae3ced3675cf4b963b35
linuxlinux>= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < c321e99d2725d11f7e6a4ebd9ce752259f0bae81c321e99d2725d11f7e6a4ebd9ce752259f0bae81
linuxlinux>= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < ca26ca5e2f3eeb3e6fe699cd6effa3b4b2aa8698ca26ca5e2f3eeb3e6fe699cd6effa3b4b2aa8698
linuxlinux>= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < 0e41a0f73ccb9be112a80bde3804a771633caaef0e41a0f73ccb9be112a80bde3804a771633caaef
linuxlinux>= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < fe2a35fa2c4f9c8ce5ef970eb927031387f9446afe2a35fa2c4f9c8ce5ef970eb927031387f9446a
linuxlinux>= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < 07b0caf8aeb9b82e6ecc6c292a3e47c7fcdb114807b0caf8aeb9b82e6ecc6c292a3e47c7fcdb1148
linuxlinux>= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < 59e26906b89cc35bb54476498772b45cbc32323f59e26906b89cc35bb54476498772b45cbc32323f
linuxlinux>= 446fda4f26822b2d42ab3396aafcedf38a9ff2b6 < dd44f04b9214adb68ef5684ae87a81ba03632250dd44f04b9214adb68ef5684ae87a81ba03632250
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 2.6.19 < 4.9.3244.9.324
linuxlinux_kernel>= 4.10 < 4.14.2894.14.289
linuxlinux_kernel>= 4.15 < 4.19.2534.19.253
linuxlinux_kernel>= 4.20 < 5.4.2075.4.207
linuxlinux_kernel>= 5.11 < 5.15.565.15.56
linuxlinux_kernel>= 5.16 < 5.18.135.18.13
linuxlinux_kernel>= 5.5 < 5.10.1325.10.132

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.