PT-2025-37519 · Linux+2 · Linux Kernel+2
Published
2025-09-15
·
Updated
2025-10-16
·
CVE-2022-50265
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains a data-race condition within the kcm (Kernel Connection Multiplexor) subsystem. Specifically,
kcm->rx psock can be read without a lock in the kcm rfree() function, leading to potential inconsistencies when accessed concurrently. This issue was identified through Kernel Concurrency Sanitizer (KCSAN) reporting and syzbot testing, revealing a data-race in kcm rcv strparser and kcm rfree. The vulnerability involves writes and reads to memory locations during socket operations, potentially triggered by functions like kcm recvmsg, strp recv, and tcp read sock.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse