CVE-2022-49344: Linux Kernel
Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix a data-race in unix_dgram_peer_wake_me(). unix_dgram_poll() calls unix_dgram_peer_wake_me() without `other`'s lock held and check if its receive queue is full. Here we need to use unix_recvq_full_lockless() instead of unix_recvq_full(), otherwise KCSAN will report a data-race.
Affected products
- Linux Linux Kernel: from 3.2.75, before 3.3 (fixed in 3.3); from 3.4.111, before 3.5 (fixed in 3.5); from 3.10.95, before 3.11 (fixed in 3.11); from 3.12.52, before 3.13 (fixed in 3.13); from 3.14.59, before 3.15 (fixed in 3.15); from 3.18.26, before 3.19 (fixed in 3.19); …
Published 2025-02-26. Last modified 2026-06-17.