In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix locking in rxrpc's sendmsg
Fix three bugs in the rxrpc's sendmsg implementation:
(1) rxrpcnewclientcall() should release the socket lock when returning an error from rxrpcgetcallslot().
(2) rxrpcwaitfortxwindow_intr() will return without the call mutex held in the event that we're interrupted by a signal whilst waiting for tx space on the socket or relocking the call mutex afterwards.
Fix this by: (a) moving the unlock/lock of the call mutex up to
rxrpc_send_data() such that the lock is not held around all of
rxrpc_wait_for_tx_window*() and (b) indicating to higher callers
whether we're return with the lock dropped. Note that this means
recvmsg() will not block on this call whilst we're waiting.
(3) After dropping and regaining the call mutex, rxrpcsenddata() needs to go and recheck the state of the txpending buffer and the txtotal_len check in case we raced with another sendmsg() on the same call.
Thinking on this some more, it might make sense to have different locks for sendmsg() and recvmsg(). There's probably no need to make recvmsg() wait for sendmsg(). It does mean that recvmsg() can return MSG_EOR indicating that a call is dead before a sendmsg() to that call returns - but that can currently happen anyway.
Without fix (2), something like the following can be induced:
WARNING: bad unlock balance detected!
5.16.0-rc6-syzkaller #0 Not tainted
-------------------------------------
syz-executor011/3597 is trying to release lock (&call->user_mutex) at:
[<ffffffff885163a3>] rxrpc_do_sendmsg+0xc13/0x1350 net/rxrpc/sendmsg.c:748
but there are no more locks to release!
other info that might help us debug this:
no locks held by syz-executor011/3597.
...
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106
print_unlock_imbalance_bug include/trace/events/lock.h:58 [inline]
__lock_release kernel/locking/lockdep.c:5306 [inline]
lock_release.cold+0x49/0x4e kernel/locking/lockdep.c:5657
__mutex_unlock_slowpath+0x99/0x5e0 kernel/locking/mutex.c:900
rxrpc_do_sendmsg+0xc13/0x1350 net/rxrpc/sendmsg.c:748
rxrpc_sendmsg+0x420/0x630 net/rxrpc/af_rxrpc.c:561
sock_sendmsg_nosec net/socket.c:704 [inline]
sock_sendmsg+0xcf/0x120 net/socket.c:724
____sys_sendmsg+0x6e8/0x810 net/socket.c:2409
___sys_sendmsg+0xf3/0x170 net/socket.c:2463
__sys_sendmsg+0xe5/0x1b0 net/socket.c:2492
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x44/0xae
[Thanks to Hawkins Jiawei and Khalid Masum for their attempts to fix this]
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49998.json",
"cna_assigner": "Linux"
}[
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c"
},
"id": "CVE-2022-49998-0c14aa10",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@79e2ca7aa96e80961828ab6312264633b66183cc",
"digest": {
"line_hashes": [
"338131756657795442599536820379739904350",
"300580479246357462035620929597030189747",
"18315106498028324431084875056135819678",
"328670360904007706538356251191989862099",
"86832605282886959852996015445646964236",
"234519662685693751064772813750536768349",
"26244750231094459601498335817683027379",
"124571104427194983601529120602280271933",
"235178301171159936865261673341556016883",
"142926989123451137171264434566471936013",
"302706256883425620747815859569878072108",
"140018356819152542253874646440458617478",
"262849747976053018879998035642368540604",
"275056818738404041244854471756701800436",
"63170221709429373219519721714668256701",
"287101259239425327400564657135855626500",
"246724100747045381236470916380257892675",
"130097936970241839591092313754919286963",
"101915017861087917332413819036951134638",
"220483189972812737683557636212939878934",
"96208518899623132398423398546001545082",
"181084509271697118814628794392960597788",
"160706465064695143711882424637052406763",
"204896502455902144835744224637311940030",
"324196324395475312665945906563930441014",
"182033702656911011320884099125204715986",
"31210968364056423034341600533546399099",
"82329840012904084624447803178811305419",
"198723996514347289853227577624527654015",
"38936947340456214434710633195959450685",
"174174291454044171457884848187798574744",
"110783551265747329190857128162258686802",
"293006700792309816205544001264024958932",
"177057191286524381095458504527562497665",
"5326794038867423010779932861586829534",
"220187891791877504154171477405338483223",
"152832942219909519628217630588054332546",
"226478275110947563397422419584899067325",
"265024520760651811439756542189554410137",
"104964371661280256703259712790603198703",
"229497334186095209755221347982587272314",
"182472864865265686863969802727668372702",
"121985587932022534240834972617377437040",
"168438479703145080468556211775354783230",
"172326108197403238843627996293699062085",
"92282771623527374667740454131161817701",
"161045590051224837712903777741901894646",
"235020873023369173783250305768167475553",
"44891910059909054840488758108715068404",
"265595560550290033414038135101486891045",
"193952997713931270609159223028966721320",
"141744519431284403679806051170015392193",
"165902558156418959346181518628957083683",
"102070889581906691014276706728216630406",
"45522001864009026123808685022019956416",
"292817065232051667333659402997805688951",
"288498706820625758104970793364962571793",
"94204912735367337573066878455664186131",
"200186780555385522375860421991599247774",
"81947980443702833099198420079548957291",
"13911865089212560245474229774628267232",
"153646432673880930920034542004703251881",
"229586928995654885227688055746612502369",
"34120416066857067342369864235942747304",
"246020699983753031975400308706051803786",
"63378577959897102598718821467704332948",
"183966757174449724786572612834708556275",
"287422040031841474615294099986430379553",
"251823649288310172577987633899981914685",
"33366239972923870949713826745315199525",
"298253125752600137660269272579166192579",
"117474752417734000212278139910867759408",
"63758617405547563513431097501919866794",
"323975085020614662079935094790131470320",
"142776946884146910494917820880557704759",
"3172934974462532501842800947709346301",
"279782730706930689145800637274040128063",
"213642750986140797693331198256171080562",
"161447916987575674025405330209671296925",
"165426968653400252024386536686759472916",
"228252653260938127189728963738644530279"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c",
"function": "rxrpc_send_data"
},
"id": "CVE-2022-49998-0e643e67",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@79e2ca7aa96e80961828ab6312264633b66183cc",
"digest": {
"function_hash": "73520374114407541743429223058848477089",
"length": 4093.0
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/call_object.c"
},
"id": "CVE-2022-49998-0f0a6bd9",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2bc769b8edb158be7379d15f36e23d66cf850053",
"digest": {
"line_hashes": [
"285322909542208007596858144172192635862",
"188485050348738170105120504742837591886",
"269990742953172503887085934022321430389",
"235265400103970062945207476393278821676",
"109662412347779569601093609946957367760"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c"
},
"id": "CVE-2022-49998-13e0c484",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@091dc91e119fdd61432347231724f4e861c6b465",
"digest": {
"line_hashes": [
"338131756657795442599536820379739904350",
"300580479246357462035620929597030189747",
"18315106498028324431084875056135819678",
"328670360904007706538356251191989862099",
"86832605282886959852996015445646964236",
"234519662685693751064772813750536768349",
"26244750231094459601498335817683027379",
"124571104427194983601529120602280271933",
"235178301171159936865261673341556016883",
"142926989123451137171264434566471936013",
"302706256883425620747815859569878072108",
"140018356819152542253874646440458617478",
"262849747976053018879998035642368540604",
"275056818738404041244854471756701800436",
"63170221709429373219519721714668256701",
"287101259239425327400564657135855626500",
"246724100747045381236470916380257892675",
"130097936970241839591092313754919286963",
"101915017861087917332413819036951134638",
"220483189972812737683557636212939878934",
"96208518899623132398423398546001545082",
"181084509271697118814628794392960597788",
"160706465064695143711882424637052406763",
"204896502455902144835744224637311940030",
"324196324395475312665945906563930441014",
"182033702656911011320884099125204715986",
"31210968364056423034341600533546399099",
"82329840012904084624447803178811305419",
"198723996514347289853227577624527654015",
"38936947340456214434710633195959450685",
"174174291454044171457884848187798574744",
"110783551265747329190857128162258686802",
"293006700792309816205544001264024958932",
"78850492334429472575616271965295587115",
"177328064262697550442701593486630381997",
"220187891791877504154171477405338483223",
"152832942219909519628217630588054332546",
"226478275110947563397422419584899067325",
"265024520760651811439756542189554410137",
"104964371661280256703259712790603198703",
"229497334186095209755221347982587272314",
"182472864865265686863969802727668372702",
"121985587932022534240834972617377437040",
"86381834614857742718992307762463808290",
"209915789372199776180228455531460603081",
"261430726030652228809309347447374392052",
"161045590051224837712903777741901894646",
"235020873023369173783250305768167475553",
"44891910059909054840488758108715068404",
"265595560550290033414038135101486891045",
"193952997713931270609159223028966721320",
"141744519431284403679806051170015392193",
"165902558156418959346181518628957083683",
"102070889581906691014276706728216630406",
"45522001864009026123808685022019956416",
"292817065232051667333659402997805688951",
"288498706820625758104970793364962571793",
"94204912735367337573066878455664186131",
"200186780555385522375860421991599247774",
"81947980443702833099198420079548957291",
"13911865089212560245474229774628267232",
"153646432673880930920034542004703251881",
"229586928995654885227688055746612502369",
"34120416066857067342369864235942747304",
"246020699983753031975400308706051803786",
"63378577959897102598718821467704332948",
"183966757174449724786572612834708556275",
"287422040031841474615294099986430379553",
"251823649288310172577987633899981914685",
"33366239972923870949713826745315199525",
"298253125752600137660269272579166192579",
"117474752417734000212278139910867759408",
"63758617405547563513431097501919866794",
"323975085020614662079935094790131470320",
"142776946884146910494917820880557704759",
"3172934974462532501842800947709346301",
"279782730706930689145800637274040128063",
"213642750986140797693331198256171080562",
"161447916987575674025405330209671296925",
"165426968653400252024386536686759472916",
"228252653260938127189728963738644530279"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c",
"function": "rxrpc_wait_for_tx_window_intr"
},
"id": "CVE-2022-49998-1973fe94",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@091dc91e119fdd61432347231724f4e861c6b465",
"digest": {
"function_hash": "334426757681656668355948846859909173649",
"length": 485.0
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/call_object.c"
},
"id": "CVE-2022-49998-1d40587a",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@79e2ca7aa96e80961828ab6312264633b66183cc",
"digest": {
"line_hashes": [
"285322909542208007596858144172192635862",
"188485050348738170105120504742837591886",
"269990742953172503887085934022321430389",
"235265400103970062945207476393278821676",
"109662412347779569601093609946957367760"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/call_object.c"
},
"id": "CVE-2022-49998-35371727",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@091dc91e119fdd61432347231724f4e861c6b465",
"digest": {
"line_hashes": [
"285322909542208007596858144172192635862",
"188485050348738170105120504742837591886",
"269990742953172503887085934022321430389",
"235265400103970062945207476393278821676",
"109662412347779569601093609946957367760"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c",
"function": "rxrpc_kernel_send_data"
},
"id": "CVE-2022-49998-4eaf378f",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2bc769b8edb158be7379d15f36e23d66cf850053",
"digest": {
"function_hash": "230184119469456046986603527196462522242",
"length": 990.0
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c"
},
"id": "CVE-2022-49998-6b88965f",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2bc769b8edb158be7379d15f36e23d66cf850053",
"digest": {
"line_hashes": [
"338131756657795442599536820379739904350",
"300580479246357462035620929597030189747",
"18315106498028324431084875056135819678",
"328670360904007706538356251191989862099",
"86832605282886959852996015445646964236",
"234519662685693751064772813750536768349",
"26244750231094459601498335817683027379",
"124571104427194983601529120602280271933",
"235178301171159936865261673341556016883",
"142926989123451137171264434566471936013",
"302706256883425620747815859569878072108",
"140018356819152542253874646440458617478",
"262849747976053018879998035642368540604",
"275056818738404041244854471756701800436",
"63170221709429373219519721714668256701",
"287101259239425327400564657135855626500",
"246724100747045381236470916380257892675",
"130097936970241839591092313754919286963",
"101915017861087917332413819036951134638",
"220483189972812737683557636212939878934",
"96208518899623132398423398546001545082",
"181084509271697118814628794392960597788",
"160706465064695143711882424637052406763",
"204896502455902144835744224637311940030",
"324196324395475312665945906563930441014",
"182033702656911011320884099125204715986",
"31210968364056423034341600533546399099",
"82329840012904084624447803178811305419",
"198723996514347289853227577624527654015",
"38936947340456214434710633195959450685",
"174174291454044171457884848187798574744",
"110783551265747329190857128162258686802",
"293006700792309816205544001264024958932",
"78850492334429472575616271965295587115",
"177328064262697550442701593486630381997",
"220187891791877504154171477405338483223",
"152832942219909519628217630588054332546",
"226478275110947563397422419584899067325",
"265024520760651811439756542189554410137",
"104964371661280256703259712790603198703",
"229497334186095209755221347982587272314",
"182472864865265686863969802727668372702",
"121985587932022534240834972617377437040",
"86381834614857742718992307762463808290",
"209915789372199776180228455531460603081",
"261430726030652228809309347447374392052",
"161045590051224837712903777741901894646",
"235020873023369173783250305768167475553",
"44891910059909054840488758108715068404",
"265595560550290033414038135101486891045",
"193952997713931270609159223028966721320",
"141744519431284403679806051170015392193",
"165902558156418959346181518628957083683",
"102070889581906691014276706728216630406",
"45522001864009026123808685022019956416",
"292817065232051667333659402997805688951",
"288498706820625758104970793364962571793",
"94204912735367337573066878455664186131",
"200186780555385522375860421991599247774",
"81947980443702833099198420079548957291",
"13911865089212560245474229774628267232",
"153646432673880930920034542004703251881",
"229586928995654885227688055746612502369",
"34120416066857067342369864235942747304",
"246020699983753031975400308706051803786",
"63378577959897102598718821467704332948",
"183966757174449724786572612834708556275",
"287422040031841474615294099986430379553",
"251823649288310172577987633899981914685",
"33366239972923870949713826745315199525",
"298253125752600137660269272579166192579",
"117474752417734000212278139910867759408",
"63758617405547563513431097501919866794",
"323975085020614662079935094790131470320",
"142776946884146910494917820880557704759",
"3172934974462532501842800947709346301",
"279782730706930689145800637274040128063",
"213642750986140797693331198256171080562",
"161447916987575674025405330209671296925",
"165426968653400252024386536686759472916",
"228252653260938127189728963738644530279"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c",
"function": "rxrpc_kernel_send_data"
},
"id": "CVE-2022-49998-6f8a522f",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@091dc91e119fdd61432347231724f4e861c6b465",
"digest": {
"function_hash": "230184119469456046986603527196462522242",
"length": 990.0
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c",
"function": "rxrpc_kernel_send_data"
},
"id": "CVE-2022-49998-88f545e0",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b0f571ecd7943423c25947439045f0d352ca3dbf",
"digest": {
"function_hash": "230184119469456046986603527196462522242",
"length": 990.0
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c",
"function": "rxrpc_kernel_send_data"
},
"id": "CVE-2022-49998-89f1926c",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@79e2ca7aa96e80961828ab6312264633b66183cc",
"digest": {
"function_hash": "230184119469456046986603527196462522242",
"length": 990.0
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/call_object.c"
},
"id": "CVE-2022-49998-8bb68fc7",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b0f571ecd7943423c25947439045f0d352ca3dbf",
"digest": {
"line_hashes": [
"285322909542208007596858144172192635862",
"188485050348738170105120504742837591886",
"269990742953172503887085934022321430389",
"235265400103970062945207476393278821676",
"109662412347779569601093609946957367760"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c",
"function": "rxrpc_send_data"
},
"id": "CVE-2022-49998-9326091b",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@091dc91e119fdd61432347231724f4e861c6b465",
"digest": {
"function_hash": "145098412547517189289147019449047884487",
"length": 3550.0
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c",
"function": "rxrpc_wait_for_tx_window_intr"
},
"id": "CVE-2022-49998-c1e3115d",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@79e2ca7aa96e80961828ab6312264633b66183cc",
"digest": {
"function_hash": "334426757681656668355948846859909173649",
"length": 485.0
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c",
"function": "rxrpc_send_data"
},
"id": "CVE-2022-49998-c34dcc23",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2bc769b8edb158be7379d15f36e23d66cf850053",
"digest": {
"function_hash": "145098412547517189289147019449047884487",
"length": 3550.0
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c",
"function": "rxrpc_wait_for_tx_window_intr"
},
"id": "CVE-2022-49998-c4c1d7a3",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2bc769b8edb158be7379d15f36e23d66cf850053",
"digest": {
"function_hash": "334426757681656668355948846859909173649",
"length": 485.0
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c",
"function": "rxrpc_wait_for_tx_window_intr"
},
"id": "CVE-2022-49998-ee206c58",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b0f571ecd7943423c25947439045f0d352ca3dbf",
"digest": {
"function_hash": "334426757681656668355948846859909173649",
"length": 485.0
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c",
"function": "rxrpc_send_data"
},
"id": "CVE-2022-49998-f612711e",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b0f571ecd7943423c25947439045f0d352ca3dbf",
"digest": {
"function_hash": "145098412547517189289147019449047884487",
"length": 3550.0
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "net/rxrpc/sendmsg.c"
},
"id": "CVE-2022-49998-f7a12631",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b0f571ecd7943423c25947439045f0d352ca3dbf",
"digest": {
"line_hashes": [
"338131756657795442599536820379739904350",
"300580479246357462035620929597030189747",
"18315106498028324431084875056135819678",
"328670360904007706538356251191989862099",
"86832605282886959852996015445646964236",
"234519662685693751064772813750536768349",
"26244750231094459601498335817683027379",
"124571104427194983601529120602280271933",
"235178301171159936865261673341556016883",
"142926989123451137171264434566471936013",
"302706256883425620747815859569878072108",
"140018356819152542253874646440458617478",
"262849747976053018879998035642368540604",
"275056818738404041244854471756701800436",
"63170221709429373219519721714668256701",
"287101259239425327400564657135855626500",
"246724100747045381236470916380257892675",
"130097936970241839591092313754919286963",
"101915017861087917332413819036951134638",
"220483189972812737683557636212939878934",
"96208518899623132398423398546001545082",
"181084509271697118814628794392960597788",
"160706465064695143711882424637052406763",
"204896502455902144835744224637311940030",
"324196324395475312665945906563930441014",
"182033702656911011320884099125204715986",
"31210968364056423034341600533546399099",
"82329840012904084624447803178811305419",
"198723996514347289853227577624527654015",
"38936947340456214434710633195959450685",
"174174291454044171457884848187798574744",
"110783551265747329190857128162258686802",
"293006700792309816205544001264024958932",
"78850492334429472575616271965295587115",
"177328064262697550442701593486630381997",
"220187891791877504154171477405338483223",
"152832942219909519628217630588054332546",
"226478275110947563397422419584899067325",
"265024520760651811439756542189554410137",
"104964371661280256703259712790603198703",
"229497334186095209755221347982587272314",
"182472864865265686863969802727668372702",
"121985587932022534240834972617377437040",
"86381834614857742718992307762463808290",
"209915789372199776180228455531460603081",
"261430726030652228809309347447374392052",
"161045590051224837712903777741901894646",
"235020873023369173783250305768167475553",
"44891910059909054840488758108715068404",
"265595560550290033414038135101486891045",
"193952997713931270609159223028966721320",
"141744519431284403679806051170015392193",
"165902558156418959346181518628957083683",
"102070889581906691014276706728216630406",
"45522001864009026123808685022019956416",
"292817065232051667333659402997805688951",
"288498706820625758104970793364962571793",
"94204912735367337573066878455664186131",
"200186780555385522375860421991599247774",
"81947980443702833099198420079548957291",
"13911865089212560245474229774628267232",
"153646432673880930920034542004703251881",
"229586928995654885227688055746612502369",
"34120416066857067342369864235942747304",
"246020699983753031975400308706051803786",
"63378577959897102598718821467704332948",
"183966757174449724786572612834708556275",
"287422040031841474615294099986430379553",
"251823649288310172577987633899981914685",
"33366239972923870949713826745315199525",
"298253125752600137660269272579166192579",
"117474752417734000212278139910867759408",
"63758617405547563513431097501919866794",
"323975085020614662079935094790131470320",
"142776946884146910494917820880557704759",
"3172934974462532501842800947709346301",
"279782730706930689145800637274040128063",
"213642750986140797693331198256171080562",
"161447916987575674025405330209671296925",
"165426968653400252024386536686759472916",
"228252653260938127189728963738644530279"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49998.json"