CVE-2022-49957: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: kcm: fix strp_init() order and cleanup strp_init() is called just a few lines above this csk->sk_user_data check, it also initializes strp->work etc., therefore, it is unnecessary to call strp_done() to cancel the freshly initialized work. And if sk_user_data is already used by KCM, psock->strp should not be touched, particularly strp->work state, so we need to move strp_init() after the csk->sk_user_data check. This also makes a lockdep warning reported by syzbot go away.

Affected products

  • Linux Linux Kernel: from 4.9.84, before 4.10 (fixed in 4.10); from 4.9.100, before 4.10 (fixed in 4.10); from 4.14.22, before 4.14.293 (fixed in 4.14.293); from 4.14.41, before 4.15 (fixed in 4.15); from 4.15.1, before 4.19.258 (fixed in 4.19.258); from 4.20, before 5.4.213 (fixed in 5.4.213); …

Published 2025-06-18. Last modified 2026-06-17.