CVE-2022-49344

Local service interruption via AF_UNIX receive-queue race

Published Feb 26, 2025 · Updated May 23, 2026

A race condition in Linux kernel AF_UNIX datagram polling allows local users to interrupt service through concurrent socket activity. unix_dgram_peer_wake_me() reads another socket's receive-queue fullness without holding its lock when called by unix_dgram_poll(). Low-privilege local access and a difficult race are required; successful triggering can hang affected socket operations without reported data disclosure or modification.

CVSS severity4.7
Medium
EPSS probability0.19%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

A race condition in Linux kernel AF_UNIX datagram polling allows local users to interrupt service through concurrent socket activity. unix_dgram_peer_wake_me() reads another socket's receive-queue fullness without holding its lock when called by unix_dgram_poll(). Low-privilege local access and a difficult race are required; successful triggering can hang affected socket operations without reported data disclosure or modification.

The record

CVE
CVE-2022-49344
Published
Feb 26, 2025
Updated
May 23, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-362, T1499
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Feb 26, 2025CVE publishedPublication date reported by the CVE source.
  2. May 23, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=2.6.32.70 <2.6.33
  2. Affected versionversion=3.10.95 <3.11
  3. Affected versionversion=3.12.52 <3.13
  4. Affected versionversion=3.14.59 <3.15
  5. Affected versionversion=3.18.26 <3.19
  6. Affected versionversion=3.2.75 <3.3
  7. Affected versionversion=3.4.111 <3.5
  8. Affected versionversion=4.1.15 <4.2
  9. Affected versionversion=4.2.8 <4.3
  10. Affected versionversion=4.3.3 <4.4
  11. Affected versionversion=4.4
  12. Affected versionversion=58a6a46a036ce81a2a8ecaa6fc1537c894349e3f
  13. Affected versionversion=5c77e26862ce604edea05b3442ed765e9756fe0f
  14. Affected versionversion=60bc010667ef06e0fb08d5ec599c0977adc2ac72
  15. Affected versionversion=72032798034d921ed565e3bf8dfdc3098f6473e2
  16. Affected versionversion=7d267278a9ece963d77eefec61630223fce08c6c <556720013c36c193d9cbfb06e7b33e51f0c39fbf
  17. Affected versionversion=7d267278a9ece963d77eefec61630223fce08c6c <662a80946ce13633ae90a55379f1346c10f0c432
  18. Affected versionversion=7d267278a9ece963d77eefec61630223fce08c6c <71e8bfc7f838cabc60cba24e09ca84c4f8321ab2
  19. Affected versionversion=7d267278a9ece963d77eefec61630223fce08c6c <8801eb3ccd2e4e3b1a01449383e3321ae6dbd9d6
  20. Affected versionversion=7d267278a9ece963d77eefec61630223fce08c6c <95f0ba806277733bf6024e23e27e1be773701cca
  21. Affected versionversion=7d267278a9ece963d77eefec61630223fce08c6c <c61848500a3fd6867dfa4834b8c7f97133eceb9f
  22. Affected versionversion=7d267278a9ece963d77eefec61630223fce08c6c <c926ae58f24f7bd55aa2ea4add9f952032507913
  23. Affected versionversion=9964b4c4ee925b2910723e509abd7241cff1ef84
  24. Affected versionversion=9d054f57adc981a5f503d5eb9b259aa450b90dc5
  25. Affected versionversion=a3b0f6e8a21ef02f69a15abac440572d8cde8c2a
  26. Affected versionversion=bad967fdd8ecbdd171f5f243657be033d2d081a7
  27. Affected versionversion=da8db0830a2ce63f628150307a01a315f5081202
  28. Affected versionversion=ec54d5ae9d298abf01c273233de9f2bc25d80475

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=2.6.32.70 <2.6.33; version=3.10.95 <3.11; version=3.12.52 <3.13; version=3.14.59 <3.15; version=3.18.26 <3.19; version=3.2.75 <3.3; version=3.4.111 <3.5; version=4.1.15 <4.2; version=4.2.8 <4.3; version=4.3.3 <4.4; version=4.4; version=58a6a46a036ce81a2a8ecaa6fc1537c894349e3f; version=5c77e26862ce604edea05b3442ed765e9756fe0f; version=60bc010667ef06e0fb08d5ec599c0977adc2ac72; version=72032798034d921ed565e3bf8dfdc3098f6473e2; version=7d267278a9ece963d77eefec61630223fce08c6c <556720013c36c193d9cbfb06e7b33e51f0c39fbf; version=7d267278a9ece963d77eefec61630223fce08c6c <662a80946ce13633ae90a55379f1346c10f0c432; version=7d267278a9ece963d77eefec61630223fce08c6c <71e8bfc7f838cabc60cba24e09ca84c4f8321ab2; version=7d267278a9ece963d77eefec61630223fce08c6c <8801eb3ccd2e4e3b1a01449383e3321ae6dbd9d6; version=7d267278a9ece963d77eefec61630223fce08c6c <95f0ba806277733bf6024e23e27e1be773701cca; version=7d267278a9ece963d77eefec61630223fce08c6c <c61848500a3fd6867dfa4834b8c7f97133eceb9f; version=7d267278a9ece963d77eefec61630223fce08c6c <c926ae58f24f7bd55aa2ea4add9f952032507913; version=9964b4c4ee925b2910723e509abd7241cff1ef84; version=9d054f57adc981a5f503d5eb9b259aa450b90dc5; version=a3b0f6e8a21ef02f69a15abac440572d8cde8c2a; version=bad967fdd8ecbdd171f5f243657be033d2d081a7; version=da8db0830a2ce63f628150307a01a315f5081202; version=ec54d5ae9d298abf01c273233de9f2bc25d80475

Published CVSS scores

4.7CISA-ADPCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
4.7NIST NVDCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
T1499Endpoint Denial of Service

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo