
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-49950 is a vulnerability in the Linux kernel's fastrpc subsystem that was disclosed on June 18, 2025. The vulnerability affects the probe session-duplication overflow check mechanism in the fastrpc subsystem, where the session count is incorrectly incremented even when no more sessions are available (NVD, Wiz).
The vulnerability exists in the fastrpc subsystem's session handling mechanism. Specifically, when fastrpcsessionalloc() is called during open() operations, the probe session-duplication overflow check has a flaw where it continues to increment the session count even in cases where no more sessions are available. This can result in memory corruption beyond the boundaries of the fixed-size slab-allocated session array (NVD, Wiz).
When exploited, this vulnerability can lead to memory corruption in the Linux kernel. This could potentially result in system instability, denial of service conditions, or possible privilege escalation depending on the specific exploitation scenario (Wiz).
The vulnerability has been addressed through patches in various Linux distributions. Ubuntu has released fixes for multiple versions, including Ubuntu 20.04 LTS which received security updates. Users are advised to update their Linux kernel to a version that includes the fix (Ubuntu, Wiz).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."