cbcvebase.
CVE-2022-50764
published 2025-12-24

CVE-2022-50764: In the Linux kernel, the following vulnerability has been resolved: ipv6/sit: use DEV_STATS_INC() to avoid data-races syzbot/KCSAN reported that multiple cpus…

PriorityP422medium6.2
EPSS
0.22%
12.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6/sit: use DEV_STATS_INC() to avoid data-races syzbot/KCSAN reported that multiple cpus are updating dev->stats.tx_error concurrently. This is because sit tunnels are NETIF_F_LLTX, meaning their ndo_start_xmit() is not protected by a spinlock. While original KCSAN report was about tx path, rx path has the same issue.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 8df40d1033d64597dcf1efd4f7547e817f7a953b < 222cc04356984f3f98acfa756a69d4bed7c501ac222cc04356984f3f98acfa756a69d4bed7c501ac
linuxlinux>= 8df40d1033d64597dcf1efd4f7547e817f7a953b < 4eed93bb3e57b8cc78d17166a14e40a73276015a4eed93bb3e57b8cc78d17166a14e40a73276015a
linuxlinux>= 8df40d1033d64597dcf1efd4f7547e817f7a953b < 207501a986831174df09a36a8cb62a28f92f0dc8207501a986831174df09a36a8cb62a28f92f0dc8
linuxlinux>= 8df40d1033d64597dcf1efd4f7547e817f7a953b < cb34b7cf17ecf33499c9298943f85af247abc1e9cb34b7cf17ecf33499c9298943f85af247abc1e9
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 2.6.37 < 5.15.865.15.86
linuxlinux_kernel>= 5.16.0 < 6.0.166.0.16
linuxlinux_kernel>= 6.1.0 < 6.1.26.1.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.