CVE-2022-49596

Service interruption via unsynchronized TCP sysctl reads

Published Feb 26, 2025 · Updated May 23, 2026

A race condition in the Linux TCP stack allows local users to interrupt service by changing tcp_min_snd_mss during concurrent reads. Readers in net/ipv4/tcp_output.c and net/ipv4/tcp_timer.c access the shared sysctl without READ_ONCE, so a concurrent write can produce an inconsistent value. Exploitation requires low local privileges and precise timing; the documented consequence is availability loss, with no reported data disclosure or modification.

CVSS severity4.7
Medium
EPSS probability0.18%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

A race condition in the Linux TCP stack allows local users to interrupt service by changing tcp_min_snd_mss during concurrent reads. Readers in net/ipv4/tcp_output.c and net/ipv4/tcp_timer.c access the shared sysctl without READ_ONCE, so a concurrent write can produce an inconsistent value. Exploitation requires low local privileges and precise timing; the documented consequence is availability loss, with no reported data disclosure or modification.

The record

CVE
CVE-2022-49596
Published
Feb 26, 2025
Updated
May 23, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-362, T1499
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Feb 26, 2025CVE publishedPublication date reported by the CVE source.
  2. May 23, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=2efabe3e1491f10bf3cf82ae1a371755ba054a1b
  2. Affected versionversion=3.16.69 <3.17
  3. Affected versionversion=4.14.127 <4.15
  4. Affected versionversion=4.19.52 <4.20
  5. Affected versionversion=4.4.182 <4.5
  6. Affected versionversion=4.9.182 <4.10
  7. Affected versionversion=5.1.11 <5.2
  8. Affected versionversion=5.2
  9. Affected versionversion=5f3e2bf008c2221478101ee72f5cb4654b9fc363 <0d8a39feb58910a7f7746b1770ee5578cc551fe6
  10. Affected versionversion=5f3e2bf008c2221478101ee72f5cb4654b9fc363 <0fc9357282df055e30990b29f4b7afa53ab42cdb
  11. Affected versionversion=5f3e2bf008c2221478101ee72f5cb4654b9fc363 <78eb166cdefcc3221c8c7c1e2d514e91a2eb5014
  12. Affected versionversion=5f3e2bf008c2221478101ee72f5cb4654b9fc363 <97992e8feff33b3ae154a113ec398546bbacda80
  13. Affected versionversion=5f3e2bf008c2221478101ee72f5cb4654b9fc363 <fdb96b69f5909ffcdd6f1e0902219fc6d7689ff7
  14. Affected versionversion=6b7e7997ad3505db7de85ff12276fc84659481d3
  15. Affected versionversion=7f9f8a37e563c67b24ccd57da1d541a95538e8d9
  16. Affected versionversion=8e39cbc03dafa3731d22533f869bf326c0e6e6f8
  17. Affected versionversion=cd6f35b8421ff20365ff711c0ac7647fd70e9af7
  18. Affected versionversion=e757d052f3b8ce739d068a1e890643376c16b7a9

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=2efabe3e1491f10bf3cf82ae1a371755ba054a1b; version=3.16.69 <3.17; version=4.14.127 <4.15; version=4.19.52 <4.20; version=4.4.182 <4.5; version=4.9.182 <4.10; version=5.1.11 <5.2; version=5.2; version=5f3e2bf008c2221478101ee72f5cb4654b9fc363 <0d8a39feb58910a7f7746b1770ee5578cc551fe6; version=5f3e2bf008c2221478101ee72f5cb4654b9fc363 <0fc9357282df055e30990b29f4b7afa53ab42cdb; version=5f3e2bf008c2221478101ee72f5cb4654b9fc363 <78eb166cdefcc3221c8c7c1e2d514e91a2eb5014; version=5f3e2bf008c2221478101ee72f5cb4654b9fc363 <97992e8feff33b3ae154a113ec398546bbacda80; version=5f3e2bf008c2221478101ee72f5cb4654b9fc363 <fdb96b69f5909ffcdd6f1e0902219fc6d7689ff7; version=6b7e7997ad3505db7de85ff12276fc84659481d3; version=7f9f8a37e563c67b24ccd57da1d541a95538e8d9; version=8e39cbc03dafa3731d22533f869bf326c0e6e6f8; version=cd6f35b8421ff20365ff711c0ac7647fd70e9af7; version=e757d052f3b8ce739d068a1e890643376c16b7a9

Published CVSS scores

4.7NIST NVDCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
T1499Endpoint Denial of Service

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo