CVE-2022-49967: Linux Kernel

Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a data-race around bpf_jit_limit. While reading bpf_jit_limit, it can be changed concurrently via sysctl, WRITE_ONCE() in __do_proc_doulongvec_minmax(). The size of bpf_jit_limit is long, so we need to add a paired READ_ONCE() to avoid load-tearing.

Affected products

  • Linux Linux Kernel: from 4.9.190, before 4.10 (fixed in 4.10); from 4.14.140, before 4.15 (fixed in 4.15); from 4.19.47, before 5.19.8 (fixed in 5.19.8); version 6.0 only

Published 2025-06-18. Last modified 2026-06-17.