CVE-2022-49672

In the Linux kernel, the following vulnerability has been resolved: net: tun: unlink NAPI from device on destruction Syzbot found a race between tun file and device destruction. NAPIs live in struct tun_file which can get destroyed before the netdev so we have to del them explicitly. The current code is missing deleting the NAPI if the queue was detached first.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.19:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.19:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.19:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.19:rc4:*:*:*:*:*:*

History

24 Oct 2025, 15:52

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:5.19:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.19:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.19:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.19:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net: tun: unlink NAPI from device on destruction Syzbot encontró una ejecución entre el archivo tun y la destrucción del dispositivo. Las NAPI se encuentran en struct tun_file, que puede destruirse antes que netdev, por lo que debemos eliminarlas explícitamente. Falta el código actual que elimina la NAPI si la cola se separó primero.
CWE NVD-CWE-noinfo
References () https://git.kernel.org/stable/c/3b9bc84d311104906d2b4995a9a02d7b7ddab2db - () https://git.kernel.org/stable/c/3b9bc84d311104906d2b4995a9a02d7b7ddab2db - Patch
References () https://git.kernel.org/stable/c/8145f77d38de4f88b8a69e1463f5c09ba189d77c - () https://git.kernel.org/stable/c/8145f77d38de4f88b8a69e1463f5c09ba189d77c - Patch
References () https://git.kernel.org/stable/c/82e729aee59acefe135fceffadcbc5b86dd4f1b9 - () https://git.kernel.org/stable/c/82e729aee59acefe135fceffadcbc5b86dd4f1b9 - Patch
References () https://git.kernel.org/stable/c/8661d4b8faa2f7ee7a559969c0a7c57f077b1728 - () https://git.kernel.org/stable/c/8661d4b8faa2f7ee7a559969c0a7c57f077b1728 - Patch
References () https://git.kernel.org/stable/c/a8cf919022373c97a84fe596bbea544f909c485d - () https://git.kernel.org/stable/c/a8cf919022373c97a84fe596bbea544f909c485d - Patch
References () https://git.kernel.org/stable/c/bec1be0a745ab420718217e3e0d9542a75108989 - () https://git.kernel.org/stable/c/bec1be0a745ab420718217e3e0d9542a75108989 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux
Linux linux Kernel

26 Feb 2025, 07:01

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 07:01

Updated : 2025-10-24 15:52


NVD link : CVE-2022-49672

Mitre link : CVE-2022-49672

CVE.ORG link : CVE-2022-49672


JSON object : View

Products Affected

linux

  • linux_kernel