Improper locking in Linux kernel - CVE-2022-50070

 

Improper locking in Linux kernel - CVE-2022-50070

Published: June 20, 2025 / Updated: June 21, 2025


Vulnerability identifier: #VU111594
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-50070
CWE-ID: CWE-667
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the mptcp_sendmsg_frag(), mptcp_subflow_get_send() and __mptcp_push_pending() functions in net/mptcp/protocol.c. A local user can perform a denial of service (DoS) attack.


Affected software

Linux kernel
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel (Red Hat package)
kernel-rt (Red Hat package)
linux-aws-fips (Ubuntu package)
linux (Ubuntu package)
linux-gcp (Ubuntu package)
linux-kvm (Ubuntu package)
linux-intel-iot-realtime (Ubuntu package)
linux-raspi (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-5.15 (Ubuntu package)

How to mitigate CVE-2022-50070

Install update from vendor's repository.

Linux kernel - addressed in versions 5.19.4, 6.0
kernel (Red Hat package) - addressed in versions 4.18.0-305.179.1.el8_4, 4.18.0-372.166.1.el8_6, 5.14.0-70.151.1.el9_0
kernel-rt (Red Hat package) - update to 5.14.0-70.151.1.rt21.223.el9_0
linux-aws-fips (Ubuntu package) - addressed in versions 5.15.0.163.94, 5.15.0-163.173+fips1, 5.15.0.1097.87, 5.15.0.1097.93, 5.15.0-1097.104+fips1, 5.15.0-1097.106+fips1
linux (Ubuntu package) - addressed in versions 5.15.0.163.140, 5.15.0.163.158, 5.15.0-163.173, 5.15.0.163.173~20.04.1, 5.15.0-163.173~20.04.1, 5.15.0-1038.38, 5.15.0.1038.40, 5.15.0-1049.49, 5.15.0.1049.49, 5.15.0.1049.49~20.04.1, 5.15.0-1049.49~20.04.1, 5.15.0.1061.64, 5.15.0-1061.65, 5.15.0.1091.87, 5.15.0-1091.94, 5.15.0.1091.94~20.04.1, 5.15.0-1091.94~20.04.1, 5.15.0.1092.92, 5.15.0-1092.93, 5.15.0.1092.98~20.04.1, 5.15.0-1092.98~20.04.1, 5.15.0.1094.90, 5.15.0-1094.100, 5.15.0.1094.100~20.04.1, 5.15.0-1094.100~20.04.1, 5.15.0.1097.100, 5.15.0-1097.104, 5.15.0-1097.104~20.04.1, 5.15.0.1097.104~20.04.1, 5.15.0-1097.106~20.04.1, 5.15.0.1097.106~20.04.1
linux-gcp (Ubuntu package) - addressed in versions 5.15.0.1080.79, 5.15.0-1080.88, 5.15.0.1093.92, 5.15.0-1093.99, 5.15.0.1097.93, 5.15.0-1097.106
linux-kvm (Ubuntu package) - addressed in versions 5.15.0.1089.85, 5.15.0-1089.94
linux-intel-iot-realtime (Ubuntu package) - addressed in versions 5.15.0-1089.91, 5.15.0.1089.93, 5.15.0.1096.100, 5.15.0-1096.105
linux-raspi (Ubuntu package) - addressed in versions 5.15.0.1091.89, 5.15.0-1091.94
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1101.86, 5.15.0-1101.110+fips1
linux-azure (Ubuntu package) - addressed in versions 5.15.0.1101.99, 5.15.0-1101.110
linux-azure-5.15 (Ubuntu package) - addressed in versions 5.15.0-1102.111~20.04.1, 5.15.0.1102.111~20.04.1

External References

Related Security Bulletins