PT-2025-37513 · Linux+1 · Linux Kernel+1

Published

2022-12-04

·

Updated

2025-09-15

·

CVE-2022-50259

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists in the sock map free() function within the kernel's bpf and sockmap implementation. Specifically, sock map free() calls release sock(sk) without holding a reference to the socket, potentially leading to a use-after-free condition. This issue was identified through testing and is similar to a previously addressed problem in sock hash free().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2026-05954
CVE-2022-50259

Affected Products

Astra Linux
Linux Kernel