« Volver al listado

CVE-2022-49957

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

kcm: fix strp_init() order and cleanup

strp_init() is called just a few lines above this csk->sk_user_data check, it also initializes strp->work etc., therefore, it is unnecessary to call strp_done() to cancel the freshly initialized work.

And if sk_user_data is already used by KCM, psock->strp should not be touched, particularly strp->work state, so we need to move strp_init() after the csk->sk_user_data check.

This also makes a lockdep warning reported by syzbot go away.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-49957",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "44890e9ff771ef11777b2d1ebf8589255eb12502",
              "lessThan": "473f394953216614087f4179e55cdf0cf616a13b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e5571240236c5652f3e079b1d5866716a7ad819c",
              "lessThan": "a8a0c321319ad64a5427d6172cd9c23b4d6ca1e8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e5571240236c5652f3e079b1d5866716a7ad819c",
              "lessThan": "0946ff31d1a8778787bf6708beb20f38715267cc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e5571240236c5652f3e079b1d5866716a7ad819c",
              "lessThan": "1b6666964ca1de93a7bf06e122bcf3616dbd33a9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e5571240236c5652f3e079b1d5866716a7ad819c",
              "lessThan": "55fb8c3baa8071c5d533a9ad48624e44e2a04ef5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e5571240236c5652f3e079b1d5866716a7ad819c",
              "lessThan": "f865976baa85915c7672f351b74d5974b93215f6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e5571240236c5652f3e079b1d5866716a7ad819c",
              "lessThan": "8fc29ff3910f3af08a7c40a75d436b5720efe2bf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "085cbbda4b4cc7dd2ba63806346881c2c2e10107",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "383250363daf01eb7aa3728c09ef8a4f6d8a3252",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "19042316b9e12c93bf334a04d4dd7a4e846c7311",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4.14.22",
              "lessThan": "4.14.293",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.9.84",
              "lessThan": "4.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.9.100",
              "lessThan": "4.10",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/kcm/kcmsock.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.14.293",
              "versionType": "semver",
              "lessThanOrEqual": "4.14.*"
            },
            {
              "status": "unaffected",
              "version": "4.19.258",
              "versionType": "semver",
              "lessThanOrEqual": "4.19.*"
            },
            {
              "status": "unaffected",
              "version": "5.4.213",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.142",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.66",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "5.19.8",
              "versionType": "semver",
              "lessThanOrEqual": "5.19.*"
            },
            {
              "status": "unaffected",
              "version": "6.0",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/kcm/kcmsock.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-06-18T11:15:22.897",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0946ff31d1a8778787bf6708beb20f38715267cc",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1b6666964ca1de93a7bf06e122bcf3616dbd33a9",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/473f394953216614087f4179e55cdf0cf616a13b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/55fb8c3baa8071c5d533a9ad48624e44e2a04ef5",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8fc29ff3910f3af08a7c40a75d436b5720efe2bf",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a8a0c321319ad64a5427d6172cd9c23b4d6ca1e8",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f865976baa85915c7672f351b74d5974b93215f6",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-908"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nkcm: fix strp_init() order and cleanup\n\nstrp_init() is called just a few lines above this csk->sk_user_data\ncheck, it also initializes strp->work etc., therefore, it is\nunnecessary to call strp_done() to cancel the freshly initialized\nwork.\n\nAnd if sk_user_data is already used by KCM, psock->strp should not be\ntouched, particularly strp->work state, so we need to move strp_init()\nafter the csk->sk_user_data check.\n\nThis also makes a lockdep warning reported by syzbot go away."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: kcm: corrección del orden y la limpieza de strp_init(). strp_init() se llama solo unas líneas por encima de la comprobación csk->sk_user_data; también inicializa strp->work, etc., por lo que no es necesario llamar a strp_done() para cancelar el trabajo recién inicializado. Si KCM ya utiliza sk_user_data, no se debe modificar psock->strp, en particular el estado strp->work, por lo que es necesario mover strp_init() después de la comprobación csk->sk_user_data. Esto también elimina la advertencia de lockdep reportada por syzbot."
    }
  ],
  "lastModified": "2026-06-17T05:19:37.260",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5DD8A70-F034-42A4-A740-48D356380D59",
              "versionEndExcluding": "4.10",
              "versionStartIncluding": "4.9.84"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0260526-FA42-4FB4-B047-599A719B6B88",
              "versionEndExcluding": "4.10",
              "versionStartIncluding": "4.9.100"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CE25529-E206-4232-88A9-7BEDBEF5C5A7",
              "versionEndExcluding": "4.14.293",
              "versionStartIncluding": "4.14.22"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9EC0120-5F42-4FE1-9DE9-3386113E1E28",
              "versionEndExcluding": "4.15",
              "versionStartIncluding": "4.14.41"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA722121-014F-4B12-A5E9-2E964FFEA0CA",
              "versionEndExcluding": "4.19.258",
              "versionStartIncluding": "4.15.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C373116-9E23-44BA-A6B7-87C8BF5C3B85",
              "versionEndExcluding": "5.4.213",
              "versionStartIncluding": "4.20"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D44AD643-5591-432E-BD41-C2C737F54AC0",
              "versionEndExcluding": "5.10.142",
              "versionStartIncluding": "5.5"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52AE7E2B-7BE3-4B8A-89CC-AB62434899A3",
              "versionEndExcluding": "5.15.66",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FEC7656-4CE2-424C-8830-EDB160E701C8",
              "versionEndExcluding": "5.19.8",
              "versionStartIncluding": "5.16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.15:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B4D39AF-668B-442B-8085-639A6D4FA5AC"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8BD11A3-8643-49B6-BADE-5029A0117325"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F0AD220-F6A9-4012-8636-155F1B841FAD"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A46498B3-78E1-4623-AAE1-94D29A42BE4E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}