CVE-2022-49972 is a vulnerability in the Linux kernel's XDP_SHARED_UMEM mode, specifically affecting systems using aligned mode where multiple sockets are bound to the same UMEM. This flaw leads to corrupted packets for all but the first socket due to improper initialization of DMA addresses for pre-populated XSK buffer pool entries. Rated with a CVSS score of 5.5 (Medium), this vulnerability requires local access and low privileges (AV:L/PR:L) to exploit, with no user interaction needed. Its impact is limited to high availability (A:H), meaning it can cause denial of service through packet corruption, but not confidentiality or integrity breaches. Currently, there is no evidence of active exploitation, nor are there any publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.16, < 5.19.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.0:rc2:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.