CVE-2022-49903
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-49903 is a vulnerability discovered in the Linux kernel's IPv6 routing implementation. The issue was identified and disclosed on May 1, 2025, affecting the initialization process of ip6routenetinitlate(). The vulnerability occurs when the files ipv6route or rt6stats fail to be created during initialization, yet the process continues successfully by default (NVD).

Technical details

The vulnerability manifests in the IPv6 routing subsystem of the Linux kernel. When the initialization process of ip6routenetinitlate() fails to create either the ipv6route or rt6stats files, it continues execution without proper error handling. This results in a warning during the cleanup phase in ip6routenetexitlate() when attempting to remove non-existent files. The issue triggers a WARNING condition with specific stack information showing CPU: 0 PID: 9 at fs/proc/generic.c:712 (NVD, Red Hat XML).

Impact

The impact of this vulnerability appears to be limited to generating system warnings and potential system instability. While it affects the IPv6 routing subsystem, it primarily manifests as a warning condition rather than a critical security issue (Wiz).

Mitigation and workarounds

The vulnerability has been addressed through patches in various Linux kernel versions. System administrators should update their kernel to the latest version that includes the fix. For Ubuntu systems, specific package updates are available, with Ubuntu 20.04 users needing to update to linux-image-5.15.0-1078-azure version 5.15.0-1078.87~20.04.1 (Wiz).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-gcp-5.4
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-6.8
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management