« Volver al listado

CVE-2022-49325

Estado: ModificadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

tcp: add accessors to read/set tp->snd_cwnd

We had various bugs over the years with code breaking the assumption that tp->snd_cwnd is greater than zero.

Lately, syzbot reported the WARN_ON_ONCE(!tp->prior_cwnd) added in commit 8b8a321ff72c ("tcp: fix zero cwnd in tcp_cwnd_reduction") can trigger, and without a repro we would have to spend considerable time finding the bug.

Instead of complaining too late, we want to catch where and when tp->snd_cwnd is set to an illegal value.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-49325",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5d424d5a674f782d0659a3b66d951f412901faee",
              "lessThan": "3308676ec525901bf1656014003c443a60730a04",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5d424d5a674f782d0659a3b66d951f412901faee",
              "lessThan": "5aba0ad44fb4a7fb78c5076c313456de199a3c29",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5d424d5a674f782d0659a3b66d951f412901faee",
              "lessThan": "41e191fe72282e193a7744e2fc1786b23156c9e4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5d424d5a674f782d0659a3b66d951f412901faee",
              "lessThan": "40570375356c874b1578e05c1dcc3ff7c1322dbe",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "include/net/tcp.h",
            "include/trace/events/tcp.h",
            "net/core/filter.c",
            "net/ipv4/tcp.c",
            "net/ipv4/tcp_bbr.c",
            "net/ipv4/tcp_bic.c",
            "net/ipv4/tcp_cdg.c",
            "net/ipv4/tcp_cong.c",
            "net/ipv4/tcp_cubic.c",
            "net/ipv4/tcp_dctcp.c",
            "net/ipv4/tcp_highspeed.c",
            "net/ipv4/tcp_htcp.c",
            "net/ipv4/tcp_hybla.c",
            "net/ipv4/tcp_illinois.c",
            "net/ipv4/tcp_input.c",
            "net/ipv4/tcp_ipv4.c",
            "net/ipv4/tcp_lp.c",
            "net/ipv4/tcp_metrics.c",
            "net/ipv4/tcp_nv.c",
            "net/ipv4/tcp_output.c",
            "net/ipv4/tcp_rate.c",
            "net/ipv4/tcp_scalable.c",
            "net/ipv4/tcp_vegas.c",
            "net/ipv4/tcp_veno.c",
            "net/ipv4/tcp_westwood.c",
            "net/ipv4/tcp_yeah.c",
            "net/ipv6/tcp_ipv6.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.47",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "5.17.15",
              "versionType": "semver",
              "lessThanOrEqual": "5.17.*"
            },
            {
              "status": "unaffected",
              "version": "5.18.4",
              "versionType": "semver",
              "lessThanOrEqual": "5.18.*"
            },
            {
              "status": "unaffected",
              "version": "5.19",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/net/tcp.h",
            "include/trace/events/tcp.h",
            "net/core/filter.c",
            "net/ipv4/tcp.c",
            "net/ipv4/tcp_bbr.c",
            "net/ipv4/tcp_bic.c",
            "net/ipv4/tcp_cdg.c",
            "net/ipv4/tcp_cong.c",
            "net/ipv4/tcp_cubic.c",
            "net/ipv4/tcp_dctcp.c",
            "net/ipv4/tcp_highspeed.c",
            "net/ipv4/tcp_htcp.c",
            "net/ipv4/tcp_hybla.c",
            "net/ipv4/tcp_illinois.c",
            "net/ipv4/tcp_input.c",
            "net/ipv4/tcp_ipv4.c",
            "net/ipv4/tcp_lp.c",
            "net/ipv4/tcp_metrics.c",
            "net/ipv4/tcp_nv.c",
            "net/ipv4/tcp_output.c",
            "net/ipv4/tcp_rate.c",
            "net/ipv4/tcp_scalable.c",
            "net/ipv4/tcp_vegas.c",
            "net/ipv4/tcp_veno.c",
            "net/ipv4/tcp_westwood.c",
            "net/ipv4/tcp_yeah.c",
            "net/ipv6/tcp_ipv6.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-02-26T07:01:09.323",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3308676ec525901bf1656014003c443a60730a04",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/40570375356c874b1578e05c1dcc3ff7c1322dbe",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/41e191fe72282e193a7744e2fc1786b23156c9e4",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5aba0ad44fb4a7fb78c5076c313456de199a3c29",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-617"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: add accessors to read/set tp->snd_cwnd\n\nWe had various bugs over the years with code\nbreaking the assumption that tp->snd_cwnd is greater\nthan zero.\n\nLately, syzbot reported the WARN_ON_ONCE(!tp->prior_cwnd) added\nin commit 8b8a321ff72c (\"tcp: fix zero cwnd in tcp_cwnd_reduction\")\ncan trigger, and without a repro we would have to spend\nconsiderable time finding the bug.\n\nInstead of complaining too late, we want to catch where\nand when tp->snd_cwnd is set to an illegal value."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: tcp: agregar descriptores de acceso para leer/establecer tp->snd_cwnd Tuvimos varios errores a lo largo de los años con código que rompía la suposición de que tp->snd_cwnd es mayor que cero. Últimamente, syzbot informó que se puede activar WARN_ON_ONCE(!tp->prior_cwnd) agregado en el commit 8b8a321ff72c (\"tcp: corregir cwnd cero en tcp_cwnd_reduction\"), y sin una reproducción tendríamos que dedicar un tiempo considerable a encontrar el error. En lugar de quejarnos demasiado tarde, queremos detectar dónde y cuándo tp->snd_cwnd se establece en un valor ilegal."
    }
  ],
  "lastModified": "2026-08-04T10:17:44.163",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30EAD0EB-B3D1-4A88-A3D8-4F8242E81A01",
              "versionEndExcluding": "5.15.47"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53E7AA2E-2FB4-45CA-A22B-08B4EDBB51AD",
              "versionEndExcluding": "5.17.15",
              "versionStartIncluding": "5.16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA6D643C-6D6A-4821-8A8D-B5776B8F0103",
              "versionEndExcluding": "5.18.4",
              "versionStartIncluding": "5.18"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}