๐Ÿ” CVE Alert

CVE-2022-49641

MEDIUM 4.7

sysctl: Fix data races in proc_douintvec().

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: sysctl: Fix data races in proc_douintvec(). A sysctl variable is accessed concurrently, and there is always a chance of data-race. So, all readers and writers need some basic protection to avoid load/store-tearing. This patch changes proc_douintvec() to use READ_ONCE() and WRITE_ONCE() internally to fix data-races on the sysctl side. For now, proc_douintvec() itself is tolerant to a data-race, but we still need to add annotations on the other subsystem's side.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Feb 26, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new medium vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
e7d316a02f683864a12389f8808570e37fb90aa3 < d5d54714e329f646bd7af4994fc427d88ee68936 e7d316a02f683864a12389f8808570e37fb90aa3 < d335db59f7fb3353f56e52371f1ee796ae9c8f09 e7d316a02f683864a12389f8808570e37fb90aa3 < 630c76850d554d7140232e71b5d1663e88cffb54 e7d316a02f683864a12389f8808570e37fb90aa3 < 4762b532ec9539755aab61445d5da6e1926ccb99 70cd763eb1574cac07138be91f474a661e02d694 f4cea51e9a3d536e2ca2b74a958f7c0b4ea733c3
Linux / Linux
4.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d5d54714e329f646bd7af4994fc427d88ee68936 git.kernel.org: https://git.kernel.org/stable/c/d335db59f7fb3353f56e52371f1ee796ae9c8f09 git.kernel.org: https://git.kernel.org/stable/c/630c76850d554d7140232e71b5d1663e88cffb54 git.kernel.org: https://git.kernel.org/stable/c/4762b532ec9539755aab61445d5da6e1926ccb99