cbcvebase.
CVE-2022-49903
published 2025-05-01

CVE-2022-49903: In the Linux kernel, the following vulnerability has been resolved: ipv6: fix WARNING in ip6_route_net_exit_late() During the initialization of…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
10.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix WARNING in ip6_route_net_exit_late() During the initialization of ip6_route_net_init_late(), if file ipv6_route or rt6_stats fails to be created, the initialization is successful by default. Therefore, the ipv6_route or rt6_stats file doesn't be found during the remove in ip6_route_net_exit_late(). It will cause WRNING. The following is the stack information: name 'rt6_stats' WARNING: CPU: 0 PID: 9 at fs/proc/generic.c:712 remove_proc_entry+0x389/0x460 Modules linked in: Workqueue: netns cleanup_net RIP: 0010:remove_proc_entry+0x389/0x460 PKRU: 55555554 Call Trace: ops_exit_list+0xb0/0x170 cleanup_net+0x4ea/0xb00 process_one_work+0x9bf/0x1710 worker_thread+0x665/0x1080 kthread+0x2e4/0x3a0 ret_from_fork+0x1f/0x30

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.8-1 (bookworm)linux 6.0.8-1 (bookworm)
linuxlinux
linuxlinux>= cdb1876192dbe680b3ac955717fdf7f863c1762d < 83fbf246ced54dadd7b9adc2a16efeff30ba944d83fbf246ced54dadd7b9adc2a16efeff30ba944d
linuxlinux>= cdb1876192dbe680b3ac955717fdf7f863c1762d < 381453770f731f0f43616a1cd4c759b7807a1517381453770f731f0f43616a1cd4c759b7807a1517
linuxlinux>= cdb1876192dbe680b3ac955717fdf7f863c1762d < 5dbb47ee89762da433cd8458788d7640c85f1a075dbb47ee89762da433cd8458788d7640c85f1a07
linuxlinux>= cdb1876192dbe680b3ac955717fdf7f863c1762d < 0ed71af4d017d2bd2cbb8f7254f613a4914def260ed71af4d017d2bd2cbb8f7254f613a4914def26
linuxlinux>= cdb1876192dbe680b3ac955717fdf7f863c1762d < 080589287127838046077904f34d5054ea0f895c080589287127838046077904f34d5054ea0f895c
linuxlinux>= cdb1876192dbe680b3ac955717fdf7f863c1762d < 768b3c745fe5789f2430bdab02f35a9ad1148d97768b3c745fe5789f2430bdab02f35a9ad1148d97
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 2.6.26 < 4.19.2654.19.265
linuxlinux_kernel>= 4.20 < 5.4.2245.4.224
linuxlinux_kernel>= 5.11 < 5.15.785.15.78
linuxlinux_kernel>= 5.16 < 6.0.86.0.8
linuxlinux_kernel>= 5.5 < 5.10.1545.10.154

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.