CVE-2022-49637

Source
https://cve.org/CVERecord?id=CVE-2022-49637
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49637.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49637
Downstream
Published
2025-02-26T02:23:46.711Z
Modified
2026-05-15T11:54:45.623825384Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
ipv4: Fix a data-race around sysctl_fib_sync_mem.
Details

In the Linux kernel, the following vulnerability has been resolved:

ipv4: Fix a data-race around sysctlfibsync_mem.

While reading sysctlfibsyncmem, it can be changed concurrently. So, we need to add READONCE() to avoid a data-race.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49637.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.2.0
Fixed
5.4.207
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.132
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.56
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.18.13

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49637.json"