CVE-2022-49204: bpf, sockmap: Fix more uncharged while msg has more_data
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Fix more uncharged while msg has more_data
In tcp_bpf_send_verdict(), if msg has more data after
tcp_bpf_sendmsg_redir():
tcp_bpf_send_verdict()
tosend = msg->sg.size //msg->sg.size = 22220
case __SK_REDIRECT:
sk_msg_return() //uncharged msg->sg.size(22220) sk->sk_forward_alloc
tcp_bpf_sendmsg_redir() //after tcp_bpf_sendmsg_redir, msg->sg.size=11000
goto more_data;
tosend = msg->sg.size //msg->sg.size = 11000
case __SK_REDIRECT:
sk_msg_return() //uncharged msg->sg.size(11000) to sk->sk_forward_alloc
The msg->sg.size(11000) has been uncharged twice, to fix we can charge the
remaining msg->sg.size before goto more data.
This issue can cause the following info:
WARNING: CPU: 0 PID: 9860 at net/core/stream.c:208 sk_stream_kill_queues+0xd4/0x1a0
Call Trace:
<TASK>
inet_csk_destroy_sock+0x55/0x110
__tcp_close+0x279/0x470
tcp_close+0x1f/0x60
inet_release+0x3f/0x80
__sock_release+0x3d/0xb0
sock_close+0x11/0x20
__fput+0x92/0x250
task_work_run+0x6a/0xa0
do_exit+0x33b/0xb60
do_group_exit+0x2f/0xa0
get_signal+0xb6/0x950
arch_do_signal_or_restart+0xac/0x2a0
? vfs_write+0x237/0x290
exit_to_user_mode_prepare+0xa9/0x200
syscall_exit_to_user_mode+0x12/0x30
do_syscall_64+0x46/0x80
entry_SYSCALL_64_after_hwframe+0x44/0xae
</TASK>
WARNING: CPU: 0 PID: 2136 at net/ipv4/af_inet.c:155 inet_sock_destruct+0x13c/0x260
Call Trace:
<TASK>
__sk_destruct+0x24/0x1f0
sk_psock_destroy+0x19b/0x1c0
process_one_work+0x1b3/0x3c0
worker_thread+0x30/0x350
? process_one_work+0x3c0/0x3c0
kthread+0xe6/0x110
? kthread_complete_and_exit+0x20/0x20
ret_from_fork+0x22/0x30
</TASK>
Security readout for executives and security teams
Plain-English summary
This Linux kernel flaw is in BPF sockmap message handling. Under specific redirect conditions, the kernel can mis-account socket memory and trigger kernel warnings during socket cleanup. The public record does not show confirmed exploitation, a CVSS score, or a clearly stated business impact beyond kernel warning conditions.
Executive priority
Treat this as a kernel maintenance item unless your environment relies on BPF sockmap features. There is no cited active exploitation or severity score, but kernel defects can affect stability and should be handled through normal patch governance.
Technical view
The issue is in tcp_bpf_send_verdict() when redirected sk_msg data has more_data. Remaining msg->sg.size can be uncharged twice against sk_forward_alloc. The fix charges the remaining size before looping for more data. Sources cite warnings in sk_stream_kill_queues and inet_sock_destruct.
Likely exposure
Exposure appears limited to Linux kernels with the affected BPF sockmap code path. Systems using BPF sockmap or related TCP BPF redirection are the most relevant to check. The bundle lists Linux kernel affected versions and stable commit references, but no distro-specific package matrix.
Exploitation context
No active exploitation is stated. The KEV flag is false, and the provided sources do not describe public exploit activity. The sources describe a kernel accounting defect and warning traces, not a demonstrated compromise path.
Researcher notes
Key evidence is narrow: the CVE record explains the double-uncharge condition and links stable kernel commits. It does not establish exploitability, privilege requirements, or impact beyond warning traces. Validate against upstream commits and downstream vendor backports before assigning urgency.
Mitigation direction
Check Linux vendor or distribution advisories for CVE-2022-49204 coverage.
Update affected kernels to releases containing the referenced stable fixes.
Prioritize hosts using BPF sockmap or TCP BPF redirection features.
If patching is delayed, review vendor guidance for safe interim controls.
Validation and detection
Inventory Linux kernel versions across servers, containers hosts, and appliances.
Compare deployed kernels with vendor advisories for CVE-2022-49204.
Review kernel logs for the warning locations named in the CVE record.
Confirm whether BPF sockmap functionality is used in relevant workloads.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-49204 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
0ADP providers
7Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Feb 26, 2025, 01:55 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.