cbcvebase.
CVE-2022-49918
published 2025-05-01

CVE-2022-49918: In the Linux kernel, the following vulnerability has been resolved: ipvs: fix WARNING in __ip_vs_cleanup_batch() During the initialization of…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.1th percentile
In the Linux kernel, the following vulnerability has been resolved: ipvs: fix WARNING in __ip_vs_cleanup_batch() During the initialization of ip_vs_conn_net_init(), if file ip_vs_conn or ip_vs_conn_sync fails to be created, the initialization is successful by default. Therefore, the ip_vs_conn or ip_vs_conn_sync file doesn't be found during the remove. The following is the stack information: name 'ip_vs_conn_sync' WARNING: CPU: 3 PID: 9 at fs/proc/generic.c:712 remove_proc_entry+0x389/0x460 Modules linked in: Workqueue: netns cleanup_net RIP: 0010:remove_proc_entry+0x389/0x460 Call Trace: __ip_vs_cleanup_batch+0x7d/0x120 ops_exit_list+0x125/0x170 cleanup_net+0x4ea/0xb00 process_one_work+0x9bf/0x1710 worker_thread+0x665/0x1080 kthread+0x2e4/0x3a0 ret_from_fork+0x1f/0x30

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.8-1 (bookworm)linux 6.0.8-1 (bookworm)
linuxlinux
linuxlinux>= 61b1ab4583e275af216c8454b9256de680499b19 < f08ee2aa24c076f81d84e26e213d8c6f4efd9f50f08ee2aa24c076f81d84e26e213d8c6f4efd9f50
linuxlinux>= 61b1ab4583e275af216c8454b9256de680499b19 < 7effc4ce3d1434ce6ff286866585a6e905fdbfc17effc4ce3d1434ce6ff286866585a6e905fdbfc1
linuxlinux>= 61b1ab4583e275af216c8454b9256de680499b19 < 931f56d59c854263b32075bfac56fdb3b1598d1b931f56d59c854263b32075bfac56fdb3b1598d1b
linuxlinux>= 61b1ab4583e275af216c8454b9256de680499b19 < 5ee2d6b726b0ce339e36569e5849692f4cf4595e5ee2d6b726b0ce339e36569e5849692f4cf4595e
linuxlinux>= 61b1ab4583e275af216c8454b9256de680499b19 < e724220b826e008764309d2a1f55a9434a4e1530e724220b826e008764309d2a1f55a9434a4e1530
linuxlinux>= 61b1ab4583e275af216c8454b9256de680499b19 < 3d00c6a0da8ddcf75213e004765e4a42acc71d5d3d00c6a0da8ddcf75213e004765e4a42acc71d5d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 2.6.39 < 4.19.2654.19.265
linuxlinux_kernel>= 4.20 < 5.4.2245.4.224
linuxlinux_kernel>= 5.11 < 5.15.785.15.78
linuxlinux_kernel>= 5.16 < 6.0.86.0.8
linuxlinux_kernel>= 5.5 < 5.10.1545.10.154

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.