CVE-2022-49641: Linux Kernel

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: sysctl: Fix data races in proc_douintvec(). A sysctl variable is accessed concurrently, and there is always a chance of data-race. So, all readers and writers need some basic protection to avoid load/store-tearing. This patch changes proc_douintvec() to use READ_ONCE() and WRITE_ONCE() internally to fix data-races on the sysctl side. For now, proc_douintvec() itself is tolerant to a data-race, but we still need to add annotations on the other subsystem's side.

Affected products

  • Linux Linux Kernel: from 4.4.24, before 4.5 (fixed in 4.5); from 4.7.7, before 5.10.132 (fixed in 5.10.132); from 5.11, before 5.15.56 (fixed in 5.15.56); from 5.16, before 5.18.13 (fixed in 5.18.13); version 5.19 only

Published 2025-02-26. Last modified 2026-06-17.