#VU104811 Infinite loop in Linux kernel - CVE-2022-49732
Published: February 26, 2025 / Updated: May 11, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the tls_update() function in net/tls/tls_main.c, within the tcp_bpf_update_proto() function in net/ipv4/tcp_bpf.c, within the sk_psock_init() function in net/core/skmsg.c. A remote attacker can send specially crafted packets to the system and perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/72fa0f65b56605b8a9ae9fba2082f2123f7fe017
- https://git.kernel.org/stable/c/922309e50befb0cfa5cb65e4989b7706d6578846
- https://git.kernel.org/stable/c/e34a07c0ae3906f97eb18df50902e2a01c1015b6
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.51
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.8
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19