PT-2025-25883 · Linux+2 · Linux Kernel+2
Published
2022-08-31
·
Updated
2025-11-14
·
CVE-2022-49957
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been resolved, related to the kcm module. The issue involved the incorrect ordering of the
strp init() function call, which led to unnecessary initialization and potential issues with the strp->work state. This problem also caused a lockdep warning reported by syzbot. The fix involves moving the strp init() call after the csk->sk user data check to prevent touching psock->strp when sk user data is already used by KCM.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Uninitialized Resource
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse