cbcvebase.
CVE-2022-50365
published 2025-09-17

CVE-2022-50365: In the Linux kernel, the following vulnerability has been resolved: skbuff: Account for tail adjustment during pull operations Extending the tail can have some…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.53%
41.8th percentile
In the Linux kernel, the following vulnerability has been resolved: skbuff: Account for tail adjustment during pull operations Extending the tail can have some unexpected side effects if a program uses a helper like BPF_FUNC_skb_pull_data to read partial content beyond the head skb headlen when all the skbs in the gso frag_list are linear with no head_frag - kernel BUG at net/core/skbuff.c:4219! pc : skb_segment+0xcf4/0xd2c lr : skb_segment+0x63c/0xd2c Call trace: skb_segment+0xcf4/0xd2c __udp_gso_segment+0xa4/0x544 udp4_ufo_fragment+0x184/0x1c0 inet_gso_segment+0x16c/0x3a4 skb_mac_gso_segment+0xd4/0x1b0 __skb_gso_segment+0xcc/0x12c udp_rcv_segment+0x54/0x16c udp_queue_rcv_skb+0x78/0x144 udp_unicast_rcv_skb+0x8c/0xa4 __udp4_lib_rcv+0x490/0x68c udp_rcv+0x20/0x30 ip_protocol_deliver_rcu+0x1b0/0x33c ip_local_deliver+0xd8/0x1f0 ip_rcv+0x98/0x1a4 deliver_ptype_list_skb+0x98/0x1ec __netif_receive_skb_core+0x978/0xc60 Fix this by marking these skbs as GSO_DODGY so segmentation can handle the tail updates accordingly.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 162a5a8c3aff15c449e6b38355cdf80ab4f77a5a < ff3743d00f41d803e6ab9334962b674f3b7fd0cbff3743d00f41d803e6ab9334962b674f3b7fd0cb
linuxlinux>= 3dcbdb134f329842a38f0e6797191b885ab00a00 < 668dc454bcbd1da73605201ff43f988c70848215668dc454bcbd1da73605201ff43f988c70848215
linuxlinux>= 3dcbdb134f329842a38f0e6797191b885ab00a00 < 821be5a5ab09a40ba09cb5ba354f18cf7996fea0821be5a5ab09a40ba09cb5ba354f18cf7996fea0
linuxlinux>= 3dcbdb134f329842a38f0e6797191b885ab00a00 < 8fb773eed4909ef5dc1bbeb3629a337d3336df7e8fb773eed4909ef5dc1bbeb3629a337d3336df7e
linuxlinux>= 3dcbdb134f329842a38f0e6797191b885ab00a00 < 946dd5dc4fcc4123cdfe3942b20012c4448cf89a946dd5dc4fcc4123cdfe3942b20012c4448cf89a
linuxlinux>= 3dcbdb134f329842a38f0e6797191b885ab00a00 < 331615d837f4979eb91a336a223a5c7f7886ecd5331615d837f4979eb91a336a223a5c7f7886ecd5
linuxlinux>= 3dcbdb134f329842a38f0e6797191b885ab00a00 < 2d7afdcbc9d32423f177ee12b7c93783aea338fb2d7afdcbc9d32423f177ee12b7c93783aea338fb
linuxlinux>= 4.14.145 < 4.14.3034.14.303
linuxlinux>= 4.19.74 < 4.19.2704.19.270
linuxlinux>= 4.9.194 < 4.9.3374.9.337
linuxlinux>= 5.2.16 < 5.35.3
linuxlinux>= 55fb612bef7fd237fb70068e2b6ff1cd1543a8ef < 6ac417d71b80e74b002313fcd73f7e9008e8e4576ac417d71b80e74b002313fcd73f7e9008e8e457
linuxlinux>= 821302dd0c51d29269ef73a595bdff294419e2cd < 2d59f0ca153e9573ec4f140988c0ccca0eb4181b2d59f0ca153e9573ec4f140988c0ccca0eb4181b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.14.145 < 4.14.3034.14.303
linuxlinux_kernel>= 4.19.74 < 4.19.2704.19.270
linuxlinux_kernel>= 4.9.194 < 4.9.3374.9.337
linuxlinux_kernel>= 5.11 < 5.15.865.15.86

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.