CVE-2022-49918

high

Description

In the Linux kernel, the following vulnerability has been resolved: ipvs: fix WARNING in __ip_vs_cleanup_batch() During the initialization of ip_vs_conn_net_init(), if file ip_vs_conn or ip_vs_conn_sync fails to be created, the initialization is successful by default. Therefore, the ip_vs_conn or ip_vs_conn_sync file doesn't be found during the remove. The following is the stack information: name 'ip_vs_conn_sync' WARNING: CPU: 3 PID: 9 at fs/proc/generic.c:712 remove_proc_entry+0x389/0x460 Modules linked in: Workqueue: netns cleanup_net RIP: 0010:remove_proc_entry+0x389/0x460 Call Trace: <TASK> __ip_vs_cleanup_batch+0x7d/0x120 ops_exit_list+0x125/0x170 cleanup_net+0x4ea/0xb00 process_one_work+0x9bf/0x1710 worker_thread+0x665/0x1080 kthread+0x2e4/0x3a0 ret_from_fork+0x1f/0x30 </TASK>

References

https://git.kernel.org/stable/c/f08ee2aa24c076f81d84e26e213d8c6f4efd9f50

https://git.kernel.org/stable/c/e724220b826e008764309d2a1f55a9434a4e1530

https://git.kernel.org/stable/c/931f56d59c854263b32075bfac56fdb3b1598d1b

https://git.kernel.org/stable/c/7effc4ce3d1434ce6ff286866585a6e905fdbfc1

https://git.kernel.org/stable/c/5ee2d6b726b0ce339e36569e5849692f4cf4595e

https://git.kernel.org/stable/c/3d00c6a0da8ddcf75213e004765e4a42acc71d5d

Details

Source: Mitre, NVD

Published: 2025-05-01

Updated: 2025-05-02

Risk Information

CVSS v2

Base Score: 6.2

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00024