CVE-2022-49540 addresses a race condition in the Linux kernel's rcu-tasks component, specifically during the boot process of secondary CPUs. This vulnerability affects the Linux kernel and can lead to a denial of service (system crash) due to a WARNING triggered by a race in scheduling and flushing work. Rated as MEDIUM severity with a CVSS score of 4.7, the vulnerability has a local attack vector and high attack complexity, requiring low privileges. Its potential impact is a high availability loss, as it can cause system instability or crashes during early boot. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.10.121CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.46CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.17.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.18, < 5.18.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.