4.7

CVE-2022-49594

tcp: Fix a data-race around sysctl_tcp_mtu_probe_floor.

In the Linux kernel, the following vulnerability has been resolved:

tcp: Fix a data-race around sysctl_tcp_mtu_probe_floor.

While reading sysctl_tcp_mtu_probe_floor, it can be changed concurrently.
Thus, we need to add READ_ONCE() to its reader.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.4 < 5.4.208
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.134
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.58
Linux ≫ Linux Kernel Version >= 5.16 < 5.18.15
Linux ≫ Linux Kernel Version 5.19 Update rc1
Linux ≫ Linux Kernel Version 5.19 Update rc2
Linux ≫ Linux Kernel Version 5.19 Update rc3
Linux ≫ Linux Kernel Version 5.19 Update rc4
Linux ≫ Linux Kernel Version 5.19 Update rc5
Linux ≫ Linux Kernel Version 5.19 Update rc6
Linux ≫ Linux Kernel Version 5.19 Update rc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.087
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.7 1 3.6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 4.7 1 3.6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

https://git.kernel.org/stable/c/033963b220633ed1602d458e7e4ac06afa9fefb2
Patch
https://git.kernel.org/stable/c/8e92d4423615a5257d0d871fc067aa561f597deb
Patch
https://git.kernel.org/stable/c/cc36c37f5fe066c4708e623ead96dc8f57224bf5
Patch
https://git.kernel.org/stable/c/d5bece4df6090395f891110ef52a6f82d16685db
Patch
https://git.kernel.org/stable/c/e2ecbf3f0aa88277d43908c53b99399d55729ff9
Patch