CVE-2022-49597

Source
https://cve.org/CVERecord?id=CVE-2022-49597
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49597.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-49597
Downstream
Published
2025-02-26T02:23:26.989Z
Modified
2026-07-15T01:48:50.802277083Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
tcp: Fix data-races around sysctl_tcp_base_mss.
Details

In the Linux kernel, the following vulnerability has been resolved:

tcp: Fix data-races around sysctltcpbase_mss.

While reading sysctltcpbasemss, it can be changed concurrently. Thus, we need to add READONCE() to its readers.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49597.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5d424d5a674f782d0659a3b66d951f412901faee
Fixed
30b73edc1d2459ba2c71cb58fbf84a1a6e640fbf
Fixed
514d2254c7b8aa2d257f5ffc79f0d96be2d6bfda
Fixed
4d7dea651b7fe0322be95054f64e3711afccc543
Fixed
9ca18116bc16ec31b9a3ce28ea1350badfa36128
Fixed
88d78bc097cd8ebc6541e93316c9d9bf651b13e8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49597.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.17
Fixed
5.4.208
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.134
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.58
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.18.15

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49597.json"