CVE-2022-49669·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race on unaccepted mptcp sockets When the listener socket owning the relevant request is closed, it frees the unaccepted subflows and that causes later deletion of the paired MPTCP sockets. The mptcp socket's worker can run in the time interval between such delete operations. When that happens, any access to msk->first will cause an UaF access, as the subflow cleanup did not cleared such field in the mptcp socket. Address the issue explicitly traversing the listener socket accept queue at close time and performing the needed cleanup on the pending msk. Note that the locking is a bit tricky, as we need to acquire the msk socket lock, while still owning the subflow socket one.
- Severity
- high
- Software
- Kernel
- Fixed in
- 5.18.10
- Published
- 2025-02-26
Affected versions
From: 5.17
Until: 5.18.10
Fixed in: 5.18.10
How to fix this CVE
Update your Linux kernel to version 5.18.10 or later to resolve a race condition vulnerability in MPTCP socket handling. This flaw allows local attackers with user privileges to trigger use-after-free conditions in the kernel's multipath TCP implementation. Ensure all systems running vulnerable kernel versions (5.17 through 5.18.9) are patched immediately.
sudo dnf update kernel kernel-core kernel-modulesDefensia detects this vulnerability
How to check if you are affected
- Check your current kernel version: uname -r
- Verify if you're running a vulnerable version: if [[ $(uname -r | cut -d. -f1,2) == '5.17' ]] || [[ $(uname -r | cut -d. -f1,2) == '5.18' && $(uname -r | cut -d. -f3) -lt 10 ]]; then echo 'VULNERABLE'; fi
- Inspect kernel logs for MPTCP-related errors or crashes: journalctl -u kernel | grep -i 'mptcp\|use-after-free\|uaf' | tail -20
- After patching, reboot and confirm new kernel: uname -r (should show 5.18.10 or later, or a newer stable version)
FAQ
What is CVE-2022-49669?
CVE-2022-49669 is a race condition in the Linux kernel's MPTCP (Multipath TCP) implementation that occurs when listener sockets are closed while handling unaccepted connections, leading to use-after-free memory corruption accessible to local users.
Is CVE-2022-49669 being actively exploited?
No, according to CISA's Known Exploited Vulnerabilities catalog, this vulnerability is not currently being actively exploited in the wild, though it remains a high-severity local privilege escalation risk.
What versions of Kernel are affected by CVE-2022-49669?
Linux kernel versions 5.17 through 5.18.9 are vulnerable; version 5.18.10 and later contain the fix.
How do I check if my server is vulnerable to CVE-2022-49669?
Run `uname -r` and compare your version: if it shows 5.17.x or 5.18.0 through 5.18.9, you are vulnerable and must update immediately.
Does Defensia detect CVE-2022-49669?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2022-49669 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2022-49669. Free for 1 server.
Get started free