PT-2025-37612 · Linux+1 · Linux Kernel+1

Published

2022-10-18

·

Updated

2025-09-20

·

CVE-2022-50310

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free (UAF) issue was identified in the ip6mr sk done() function within the Linux kernel. This occurs when addrconf init net() fails, leading to the release of a pointer (devconf) that is subsequently accessed in ip6mr sk done(), resulting in invalid pointer access. The vulnerability is triggered during network namespace creation via the unshare system call. The call trace indicates the issue arises from memory being freed prematurely, and then subsequently accessed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Improper Initialization

Weakness Enumeration

Related Identifiers

BDU:2026-03775
CVE-2022-50310

Affected Products

Astra Linux
Linux Kernel