CVE-2022-49672: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: tun: unlink NAPI from device on destruction Syzbot found a race between tun file and device destruction. NAPIs live in struct tun_file which can get destroyed before the netdev so we have to del them explicitly. The current code is missing deleting the NAPI if the queue was detached first.

Affected products

  • Linux Linux Kernel: from 4.15, before 4.19.251 (fixed in 4.19.251); from 4.20, before 5.4.204 (fixed in 5.4.204); from 5.5, before 5.10.129 (fixed in 5.10.129); from 5.11, before 5.15.53 (fixed in 5.15.53); from 5.16, before 5.18.10 (fixed in 5.18.10); version 5.19 only

Published 2025-02-26. Last modified 2026-08-04.