CVE-2022-49087

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 26, 2025
Updated: Feb 27, 2025
CWE ID 416

Summary

CVE-2022-49087 is a vulnerability impacting the Linux kernel where a race condition exists in the rxrpc module. Specifically, in the rxrpc_exit_net() function, the code may exit while the peer_keepalive_timer is still armed, resulting in a use-after-free scenario. This can lead to memory corruption and potential exploitation. A syzbot report documented the issue, which occurred during a netns cleanup_net workqueue process. The vulnerability was discovered during a Google Compute Engine instance running kernel version 5.17.0-syzkaller-13993-g88e6c0207623.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share