PT-2025-8704 · Linux+4 · Linux Kernel+4
Jakub Kicinski
+2
·
Published
2022-06-23
·
Updated
2025-10-24
·
CVE-2022-49732
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been resolved. The issue is related to the protection check for psock vs ULP. The
inet csk has ulp(sk) check was moved from sk psock init() to the new tcp bpf update proto() function, potentially allowing the creation of psocks for non-inet sockets. However, the destruction path for psock includes the ULP unwind, requiring the sk psock init() to fail if ULP is already present. Otherwise, it may result in the ULP looping its callbacks.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Centos
Linux Kernel
Red Hat
Suse