SB20250226645 - Infinite loop in Linux kernel net
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Infinite loop (CVE-ID: CVE-2022-49732)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the tls_update() function in net/tls/tls_main.c, within the tcp_bpf_update_proto() function in net/ipv4/tcp_bpf.c, within the sk_psock_init() function in net/core/skmsg.c. A remote attacker can send specially crafted packets to the system and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/72fa0f65b56605b8a9ae9fba2082f2123f7fe017
- https://git.kernel.org/stable/c/922309e50befb0cfa5cb65e4989b7706d6578846
- https://git.kernel.org/stable/c/e34a07c0ae3906f97eb18df50902e2a01c1015b6
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.51
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.8
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19