{"id":"DEBIAN-CVE-2022-49877","details":"In the Linux kernel, the following vulnerability has been resolved:  bpf, sockmap: Fix the sk-\u003esk_forward_alloc warning of sk_stream_kill_queues  When running `test_sockmap` selftests, the following warning appears:    WARNING: CPU: 2 PID: 197 at net/core/stream.c:205 sk_stream_kill_queues+0xd3/0xf0   Call Trace:   \u003cTASK\u003e   inet_csk_destroy_sock+0x55/0x110   tcp_rcv_state_process+0xd28/0x1380   ? tcp_v4_do_rcv+0x77/0x2c0   tcp_v4_do_rcv+0x77/0x2c0   __release_sock+0x106/0x130   __tcp_close+0x1a7/0x4e0   tcp_close+0x20/0x70   inet_release+0x3c/0x80   __sock_release+0x3a/0xb0   sock_close+0x14/0x20   __fput+0xa3/0x260   task_work_run+0x59/0xb0   exit_to_user_mode_prepare+0x1b3/0x1c0   syscall_exit_to_user_mode+0x19/0x50   do_syscall_64+0x48/0x90   entry_SYSCALL_64_after_hwframe+0x44/0xae  The root case is in commit 84472b436e76 (\"bpf, sockmap: Fix more uncharged while msg has more_data\"), where I used msg-\u003esg.size to replace the tosend, causing breakage:    if (msg-\u003eapply_bytes && msg-\u003eapply_bytes \u003c tosend)     tosend = psock-\u003eapply_bytes;","modified":"2026-09-01T16:05:33.553572357Z","published":"2025-05-01T15:16:12.653Z","upstream":["CVE-2022-49877"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49877"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49877.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49877.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49877.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}