CVE-2022-50783
published 2025-12-24CVE-2022-50783: In the Linux kernel, the following vulnerability has been resolved: mptcp: use proper req destructor for IPv6 Before, only the destructor from TCP request sock…
PriorityP422medium6.6
EPSS
0.22%
12.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
mptcp: use proper req destructor for IPv6
Before, only the destructor from TCP request sock in IPv4 was called
even if the subflow was IPv6.
It is important to use the right destructor to avoid memory leaks with
some advanced IPv6 features, e.g. when the request socks contain
specific IPv6 options.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 79c0949e9a09f6a14a6dd18dc8396029423f9b68 < 6eb02c596ec02e5897ae377e065cb7df55337a96 | 6eb02c596ec02e5897ae377e065cb7df55337a96 |
| linux | linux | >= 79c0949e9a09f6a14a6dd18dc8396029423f9b68 < bd5dc96fea4edd16d2e22f41b4dd50a4cfbeb919 | bd5dc96fea4edd16d2e22f41b4dd50a4cfbeb919 |
| linux | linux | >= 79c0949e9a09f6a14a6dd18dc8396029423f9b68 < 092953f3c4cd65f88b27b87a922f6c725f34ee04 | 092953f3c4cd65f88b27b87a922f6c725f34ee04 |
| linux | linux | >= 79c0949e9a09f6a14a6dd18dc8396029423f9b68 < 1922ea6b0ae2ea0c9a09be0eafafe1cd1069d259 | 1922ea6b0ae2ea0c9a09be0eafafe1cd1069d259 |
| linux | linux | >= 79c0949e9a09f6a14a6dd18dc8396029423f9b68 < d3295fee3c756ece33ac0d935e172e68c0a4161b | d3295fee3c756ece33ac0d935e172e68c0a4161b |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 5.11.0 < 5.15.87 | 5.15.87 |
| linux | linux_kernel | >= 5.16.0 < 6.0.18 | 6.0.18 |
| linux | linux_kernel | >= 5.6.0 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 6.1.0 < 6.1.4 | 6.1.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7hfj-fw8x-q6p6: In the Linux kernel, the following vulnerability has been resolved:
mptcp: use proper req destructor for IPv6
Before, only the destructor from TCP r
ghsa_unreviewed·2025-12-24
CVE-2022-50783 GHSA-7hfj-fw8x-q6p6: In the Linux kernel, the following vulnerability has been resolved:
mptcp: use proper req destructor for IPv6
Before, only the destructor from TCP r
In the Linux kernel, the following vulnerability has been resolved:
mptcp: use proper req destructor for IPv6
Before, only the destructor from TCP request sock in IPv4 was called
even if the subflow was IPv6.
It is important to use the right destructor to avoid memory leaks with
some advanced IPv6 features, e.g. when the request socks contain
specific IPv6 options.
OSV
CVE-2022-50783: In the Linux kernel, the following vulnerability has been resolved: mptcp: use proper req destructor for IPv6 Before, only the destructor from TCP req
osv·2025-12-24
CVE-2022-50783 CVE-2022-50783: In the Linux kernel, the following vulnerability has been resolved: mptcp: use proper req destructor for IPv6 Before, only the destructor from TCP req
In the Linux kernel, the following vulnerability has been resolved: mptcp: use proper req destructor for IPv6 Before, only the destructor from TCP request sock in IPv4 was called even if the subflow was IPv6. It is important to use the right destructor to avoid memory leaks with some advanced IPv6 features, e.g. when the request socks contain specific IPv6 options.
OSV
mptcp: use proper req destructor for IPv6
osv·2025-12-24
CVE-2022-50783 mptcp: use proper req destructor for IPv6
mptcp: use proper req destructor for IPv6
In the Linux kernel, the following vulnerability has been resolved:
mptcp: use proper req destructor for IPv6
Before, only the destructor from TCP request sock in IPv4 was called
even if the subflow was IPv6.
It is important to use the right destructor to avoid memory leaks with
some advanced IPv6 features, e.g. when the request socks contain
specific IPv6 options.
Red Hat
kernel: mptcp: use proper req destructor for IPv6
vendor_redhat·2025-12-24·CVSS 6.6
CVE-2022-50783 [MEDIUM] CWE-401 kernel: mptcp: use proper req destructor for IPv6
kernel: mptcp: use proper req destructor for IPv6
In the Linux kernel, the following vulnerability has been resolved:
mptcp: use proper req destructor for IPv6
Before, only the destructor from TCP request sock in IPv4 was called
even if the subflow was IPv6.
It is important to use the right destructor to avoid memory leaks with
some advanced IPv6 features, e.g. when the request socks contain
specific IPv6 options.
A flaw was discovered in the Linux kernel’s Multipath TCP (MPTCP) implementation where the wrong destructor function was used for IPv6 subflow request sockets. Previously, even when handling IPv6 MPTCP subflows, only the IPv4 request socket destructor was invoked, leaving IPv6-specific fields unmanaged. Under certain conditions advanced IPv6 usage scenarios—such as subflows con
Debian
CVE-2022-50783: linux - In the Linux kernel, the following vulnerability has been resolved: mptcp: use ...
vendor_debian·2022
CVE-2022-50783 CVE-2022-50783: linux - In the Linux kernel, the following vulnerability has been resolved: mptcp: use ...
In the Linux kernel, the following vulnerability has been resolved: mptcp: use proper req destructor for IPv6 Before, only the destructor from TCP request sock in IPv4 was called even if the subflow was IPv6. It is important to use the right destructor to avoid memory leaks with some advanced IPv6 features, e.g. when the request socks contain specific IPv6 options.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2022-50783 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50783 CVE-2022-50783 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50783 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
mptcp: use proper req destructor for IPv6
Before, only the destructor from TCP request sock in IPv4 was called
even if the subflow was IPv6.
It is important to use the right destructor to avoid memory leaks with
some advanced IPv6 features, e.g. when the request socks contain
specific IPv6 options.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-rt-64k-modules-internal
Bugzilla
CVE-2022-50783 kernel: mptcp: use proper req destructor for IPv6
bugzilla·2025-12-24
CVE-2022-50783 [MEDIUM] CVE-2022-50783 kernel: mptcp: use proper req destructor for IPv6
CVE-2022-50783 kernel: mptcp: use proper req destructor for IPv6
In the Linux kernel, the following vulnerability has been resolved:
mptcp: use proper req destructor for IPv6
Before, only the destructor from TCP request sock in IPv4 was called
even if the subflow was IPv6.
It is important to use the right destructor to avoid memory leaks with
some advanced IPv6 features, e.g. when the request socks contain
specific IPv6 options.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122402-CVE-2022-50783-3109@gregkh/T
https://git.kernel.org/stable/c/092953f3c4cd65f88b27b87a922f6c725f34ee04https://git.kernel.org/stable/c/1922ea6b0ae2ea0c9a09be0eafafe1cd1069d259https://git.kernel.org/stable/c/6eb02c596ec02e5897ae377e065cb7df55337a96https://git.kernel.org/stable/c/bd5dc96fea4edd16d2e22f41b4dd50a4cfbeb919https://git.kernel.org/stable/c/d3295fee3c756ece33ac0d935e172e68c0a4161b
2025-12-24
Published