Race Condition Vulnerability in Linux Kernel's VXLAN Module
CVE-2022-50405
What is CVE-2022-50405?
A race condition exists in the VXLAN implementation of the Linux kernel, which can occur when a VXLAN device is deleted while simultaneously receiving packets. This vulnerability arises when the socket object (sock) may be released after accessing vxlan_sock through sk_user_data. Consequently, subsequent operations like vxlan_ecn_decapsulate() could attempt to dereference a NULL pointer, potentially causing system crashes and instability. It is crucial for users to ensure their systems are updated to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Linux 6a93cc9052748c6355ec9d5b6c38b77f85f1cb0d
Linux 6a93cc9052748c6355ec9d5b6c38b77f85f1cb0d < 84e566d157cc22ad2da8bdd970495855fbf13d92
Linux 6a93cc9052748c6355ec9d5b6c38b77f85f1cb0d
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved