Race Condition Vulnerability in Linux Kernel's VXLAN Module
CVE-2022-50405

5.5MEDIUM

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
18 September 2025

What is CVE-2022-50405?

A race condition exists in the VXLAN implementation of the Linux kernel, which can occur when a VXLAN device is deleted while simultaneously receiving packets. This vulnerability arises when the socket object (sock) may be released after accessing vxlan_sock through sk_user_data. Consequently, subsequent operations like vxlan_ecn_decapsulate() could attempt to dereference a NULL pointer, potentially causing system crashes and instability. It is crucial for users to ensure their systems are updated to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 6a93cc9052748c6355ec9d5b6c38b77f85f1cb0d

Linux 6a93cc9052748c6355ec9d5b6c38b77f85f1cb0d < 84e566d157cc22ad2da8bdd970495855fbf13d92

Linux 6a93cc9052748c6355ec9d5b6c38b77f85f1cb0d

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.