PT-2022-7685 · Linux+5 · Linux Kernel+5

Syzbot

·

Published

2022-11-29

·

Updated

2025-11-18

·

CVE-2022-49014

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.1.0-rc5-syzkaller-00044-gcc675d22e422
Description The issue is related to a use-after-free vulnerability in the tun detach() function of the Linux kernel's tun driver. This vulnerability can be exploited to impact the confidentiality, integrity, and availability of protected information. The cause of the issue is that sock put() from tun detach() drops the last reference count for struct net, and then notifier call chain() from netdev state change() accesses that struct net. The vulnerability can be triggered by a call trace like the one reported by syzbot, which includes a read of size 8 at a specific address by the syz-executor.0 task.
Recommendations To resolve the issue, apply the patch that fixes the use-after-free in tun detach() by calling sock put() from tun detach() after all necessary accesses for struct net have been done. As a temporary workaround, consider restricting access to the tun driver to minimize the risk of exploitation.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2023-1066
BDU:2024-10088
CVE-2022-49014
INFSA-2025_6966
OESA-2025-1016
OPENSUSE-SU-2024_3983-1
OPENSUSE-SU-2024_3985-1
OPENSUSE-SU-2024_4131-1
OPENSUSE-SU-2024_4140-1
OPENSUSE-SU-2025_1213-1
OPENSUSE-SU-2025_1225-1
OPENSUSE-SU-2025_1248-1
OPENSUSE-SU-2025_1254-1
OPENSUSE-SU-2025_1259-1
OPENSUSE-SU-2025_1260-1
OPENSUSE-SU-2025_1262-1
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2024:3983-1
SUSE-SU-2024:3985-1
SUSE-SU-2024:4081-1
SUSE-SU-2024:4082-1
SUSE-SU-2024:4100-1
SUSE-SU-2024:4103-1
SUSE-SU-2024:4131-1
SUSE-SU-2024:4140-1
SUSE-SU-2024:4364-1
SUSE-SU-2025:0034-1
SUSE-SU-2025:1213-1
SUSE-SU-2025:1225-1
SUSE-SU-2025:1231-1
SUSE-SU-2025:1236-1
SUSE-SU-2025:1248-1
SUSE-SU-2025:1254-1
SUSE-SU-2025:1259-1
SUSE-SU-2025:1260-1
SUSE-SU-2025:1262-1
SUSE-SU-2025:1278-1
SUSE-SU-2025:4123-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Red Hat
Red Os
Suse