PT-2022-7427 · Linux+3 · Linux Kernel+3

·

CVE-2022-48785

·

Published

2022-02-14

·

Updated

2026-07-24

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.15.19-cloudflare-2022.2.1
Description The vulnerability is related to the mld newpack() function in the net/ipv6/mcast.c module of the Linux kernel's IPv6 implementation. It is caused by incorrect synchronization, which can lead to a denial of service. The issue arises from the use of an rcu-unsafe version of ipv6 get lladdr() after external locks were removed. This can result in a general protection fault and cause the machine to crash or stall.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the ipv6: mcast: use rcu-safe version of ipv6 get lladdr() vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06075
CVE-2022-48785
OPENSUSE-SU-2024_2947-1
RHSA-2022:7933
RHSA-2022:8267
SUSE-SU-2024:2894-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2947-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse