
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-49903 is a vulnerability discovered in the Linux kernel's IPv6 routing implementation. The issue was identified and disclosed on May 1, 2025, affecting the initialization process of ip6_route_net_init_late(). The vulnerability occurs when the files ipv6_route or rt6_stats fail to be created during initialization, yet the process continues successfully by default (NVD).
The vulnerability manifests in the IPv6 routing subsystem of the Linux kernel. When the initialization process of ip6_route_net_init_late() fails to create either the ipv6_route or rt6_stats files, it continues execution without proper error handling. This results in a warning during the cleanup phase in ip6_route_net_exit_late() when attempting to remove non-existent files. The issue triggers a WARNING condition with specific stack information showing CPU: 0 PID: 9 at fs/proc/generic.c:712 (NVD, Red Hat XML).
The impact of this vulnerability appears to be limited to generating system warnings and potential system instability. While it affects the IPv6 routing subsystem, it primarily manifests as a warning condition rather than a critical security issue (Wiz).
The vulnerability has a CVSS v3.1 Base Score of 5.5 (Medium), with attack vector being Local (AV:L), requiring low attack complexity (AC:L) and low privileges (PR:L). The vulnerability does not require user interaction (UI:N) and has no impact on confidentiality or integrity, but can affect availability (A:H) (Red Hat XML).
The vulnerability has been addressed through patches in various Linux kernel versions. System administrators should update their kernel to the latest version that includes the fix. For Ubuntu systems, specific package updates are available, with Ubuntu 20.04 users needing to update to linux-image-5.15.0-1078-azure version 5.15.0-1078.87~20.04.1 (Wiz).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."