CVE-2022-49589

Source
https://cve.org/CVERecord?id=CVE-2022-49589
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49589.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49589
Downstream
Related
Published
2025-02-26T02:23:23.070Z
Modified
2026-04-11T12:44:16.287647Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
igmp: Fix data-races around sysctl_igmp_qrv.
Details

In the Linux kernel, the following vulnerability has been resolved:

igmp: Fix data-races around sysctligmpqrv.

While reading sysctligmpqrv, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers.

This test can be packed into a helper, so such changes will be in the follow-up series after net is merged into net-next.

qrv ?: READONCE(net->ipv4.sysctligmp_qrv);

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49589.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a9fe8e29945d56f35235a3a0fba99b4cf181d211
Fixed
9eeb3a7702998bdccbfcc37997b5dd9215b9a7f7
Fixed
e20dd1b0e0ea15bee1e528536a0840dba972ca0e
Fixed
b399ffafffba39f47b731b26a5da1dc0ffc4b3ad
Fixed
c721324afc589f8ea54bae04756b150aeaae5fa4
Fixed
c2954671010cd1127d1ffa328c6e6f8e99930982
Fixed
8ebcc62c738f68688ee7c6fec2efe5bc6d3d7e60

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49589.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.18.0
Fixed
4.19.255
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.209
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.135
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.59
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.18.15

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49589.json"