CVE-2022-49571

Source
https://cve.org/CVERecord?id=CVE-2022-49571
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49571.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-49571
Downstream
Published
2025-02-26T02:23:14.182Z
Modified
2026-07-15T01:49:05.462965352Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
tcp: Fix data-races around sysctl_tcp_max_reordering.
Details

In the Linux kernel, the following vulnerability has been resolved:

tcp: Fix data-races around sysctltcpmax_reordering.

While reading sysctltcpmaxreordering, it can be changed concurrently. Thus, we need to add READONCE() to its readers.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49571.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
dca145ffaa8d39ea1904491ac81b92b7049372c0
Fixed
5e38cee24f19d19280c68f1ac8bf6790d607f60a
Fixed
50a1d3d097503a90cf84ebe120afcde37e9c33b3
Fixed
064852663308c801861bd54789d81421fa4c2928
Fixed
ce3731c61589ed73364a5b55ce34131762ef9b60
Fixed
46deb91ac8a790286ad6d24cf92e7ab0ab2582bb
Fixed
a11e5b3e7a59fde1a90b0eaeaa82320495cf8cae

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49571.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.19.0
Fixed
4.19.254
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.208
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.134
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.58
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.18.15

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49571.json"