cbcvebase.
CVE-2022-49641
published 2025-02-26

CVE-2022-49641: In the Linux kernel, the following vulnerability has been resolved: sysctl: Fix data races in proc_douintvec(). A sysctl variable is accessed concurrently, and…

PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.17%
7.1th percentile
In the Linux kernel, the following vulnerability has been resolved: sysctl: Fix data races in proc_douintvec(). A sysctl variable is accessed concurrently, and there is always a chance of data-race. So, all readers and writers need some basic protection to avoid load/store-tearing. This patch changes proc_douintvec() to use READ_ONCE() and WRITE_ONCE() internally to fix data-races on the sysctl side. For now, proc_douintvec() itself is tolerant to a data-race, but we still need to add annotations on the other subsystem's side.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.4.24 < 4.54.5
linuxlinux>= 4.7.7 < 4.84.8
linuxlinux>= e7d316a02f683864a12389f8808570e37fb90aa3 < d5d54714e329f646bd7af4994fc427d88ee68936d5d54714e329f646bd7af4994fc427d88ee68936
linuxlinux>= e7d316a02f683864a12389f8808570e37fb90aa3 < d335db59f7fb3353f56e52371f1ee796ae9c8f09d335db59f7fb3353f56e52371f1ee796ae9c8f09
linuxlinux>= e7d316a02f683864a12389f8808570e37fb90aa3 < 630c76850d554d7140232e71b5d1663e88cffb54630c76850d554d7140232e71b5d1663e88cffb54
linuxlinux>= e7d316a02f683864a12389f8808570e37fb90aa3 < 4762b532ec9539755aab61445d5da6e1926ccb994762b532ec9539755aab61445d5da6e1926ccb99
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 4.4.24 < 4.54.5
linuxlinux_kernel>= 4.7.7 < 5.10.1325.10.132
linuxlinux_kernel>= 5.11 < 5.15.565.15.56
linuxlinux_kernel>= 5.16 < 5.18.135.18.13

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.