PT-2025-8132 · Linux+3 · Linux Kernel+3

Wang Yufen

·

Published

2023-05-09

·

Updated

2025-09-29

·

CVE-2022-49204

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, related to the bpf and sockmap components. The issue arises when the tcp bpf send verdict() function is called, and the msg has more data after tcp bpf sendmsg redir(). This can cause the msg->sg.size to be uncharged twice, leading to potential problems. The vulnerability can result in warnings, such as WARNING: CPU: 0 PID: 9860 at net/core/stream.c:208 sk stream kill queues+0xd4/0x1a0 and WARNING: CPU: 0 PID: 2136 at net/ipv4/af inet.c:155 inet sock destruct+0x13c/0x260, and may cause issues with socket destruction and TCP closure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2025_16880
CVE-2022-49204
RHSA-2023:2458
RHSA-2023_2458
SUSE-SU-2025:1176-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1293-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Suse