CVE-2022-49998
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-49998 affects the Linux kernel's rxrpc sendmsg implementation. The vulnerability was discovered in June 2025 and impacts the kernel's network protocol handling, specifically related to locking mechanisms in the rxrpc subsystem (NVD).

Technical details

The vulnerability encompasses three distinct bugs in the rxrpc's sendmsg implementation: 1) rxrpc_new_client_call() failing to release the socket lock when returning an error from rxrpc_get_call_slot(), 2) rxrpc_wait_for_tx_window_intr() returning without the call mutex held during signal interruption, and 3) rxrpc_send_data() needing to recheck the tx_pending buffer and tx_total_len after dropping and regaining the call mutex (NVD, Wiz).

Impact

The vulnerability can lead to a bad unlock balance condition, potentially causing system instability. This is evidenced by warning messages indicating improper lock handling, which could result in system crashes or unpredictable behavior (NVD).

Mitigation and workarounds

The vulnerability has been fixed in various Linux kernel versions. The fix includes modifications to the locking mechanism in rxrpc's sendmsg implementation. Debian has marked this as fixed in versions 5.10.223-1 for bullseye, 6.1.137-1 for bookworm, and 6.12.31-1 for trixie (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-realtime
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • linux-oracle
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-realtime
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-core
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • kernel
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management