CVE-2022-49979: net: fix refcount bug in sk_psock_get (2)
In the Linux kernel, the following vulnerability has been resolved:
net: fix refcount bug in sk_psock_get (2)
Syzkaller reports refcount bug as follows:
------------[ cut here ]------------
refcount_t: saturated; leaking memory.
WARNING: CPU: 1 PID: 3605 at lib/refcount.c:19 refcount_warn_saturate+0xf4/0x1e0 lib/refcount.c:19
Modules linked in:
CPU: 1 PID: 3605 Comm: syz-executor208 Not tainted 5.18.0-syzkaller-03023-g7e062cda7d90 #0
<TASK>
__refcount_add_not_zero include/linux/refcount.h:163 [inline]
__refcount_inc_not_zero include/linux/refcount.h:227 [inline]
refcount_inc_not_zero include/linux/refcount.h:245 [inline]
sk_psock_get+0x3bc/0x410 include/linux/skmsg.h:439
tls_data_ready+0x6d/0x1b0 net/tls/tls_sw.c:2091
tcp_data_ready+0x106/0x520 net/ipv4/tcp_input.c:4983
tcp_data_queue+0x25f2/0x4c90 net/ipv4/tcp_input.c:5057
tcp_rcv_state_process+0x1774/0x4e80 net/ipv4/tcp_input.c:6659
tcp_v4_do_rcv+0x339/0x980 net/ipv4/tcp_ipv4.c:1682
sk_backlog_rcv include/net/sock.h:1061 [inline]
__release_sock+0x134/0x3b0 net/core/sock.c:2849
release_sock+0x54/0x1b0 net/core/sock.c:3404
inet_shutdown+0x1e0/0x430 net/ipv4/af_inet.c:909
__sys_shutdown_sock net/socket.c:2331 [inline]
__sys_shutdown_sock net/socket.c:2325 [inline]
__sys_shutdown+0xf1/0x1b0 net/socket.c:2343
__do_sys_shutdown net/socket.c:2351 [inline]
__se_sys_shutdown net/socket.c:2349 [inline]
__x64_sys_shutdown+0x50/0x70 net/socket.c:2349
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x46/0xb0
</TASK>
During SMC fallback process in connect syscall, kernel will
replaces TCP with SMC. In order to forward wakeup
smc socket waitqueue after fallback, kernel will sets
clcsk->sk_user_data to origin smc socket in
smc_fback_replace_callbacks().
Later, in shutdown syscall, kernel will calls
sk_psock_get(), which treats the clcsk->sk_user_data
as psock type, triggering the refcnt warning.
So, the root cause is that smc and psock, both will use
sk_user_data field. So they will mismatch this field
easily.
This patch solves it by using another bit(defined as
SK_USER_DATA_PSOCK) in PTRMASK, to mark whether
sk_user_data points to a psock object or not.
This patch depends on a PTRMASK introduced in commit f1ff5ce2cd5e
("net, sk_msg: Clear sk_user_data pointer on clone if tagged").
For there will possibly be more flags in the sk_user_data field,
this patch also refactor sk_user_data flags code to be more generic
to improve its maintainability.
Security readout for executives and security teams
Plain-English summary
A Linux networking flaw can misinterpret internal socket data during SMC fallback and shutdown, corrupting reference-count handling and potentially leaking memory. The supplied CVSS score is 7.8 (high), but the public description demonstrates a kernel warning rather than confirmed code execution or real-world compromise.
Executive priority
Treat this as a high-priority kernel maintenance issue, especially on shared or locally accessible Linux hosts. It does not warrant an exploitation emergency based solely on the supplied evidence. Confirm exposure promptly, deploy supported kernel fixes through normal accelerated patching, and require reboot verification.
Technical view
SMC fallback and psock both use sk_user_data. During socket replacement, an SMC pointer can be treated as a psock by sk_psock_get(), causing reference-count saturation and memory leakage. The fix tags psock pointers with SK_USER_DATA_PSOCK and generalizes flag handling. It depends on an earlier PTRMASK change.
Likely exposure
Exposure applies to Linux kernels identified as affected in the CVE data, including listed 5.17, 5.15.65, 5.19.7, and 6.0 entries. The supplied version boundaries mix releases and commit identifiers, so distribution-specific applicability requires confirmation against vendor advisories and kernel build provenance.
Exploitation context
The CVSS vector describes local, low-complexity exploitation requiring low privileges and no user interaction. The issue was reported by Syzkaller. It is not listed as KEV in the supplied bundle, and no cited evidence establishes active exploitation, a public weaponized exploit, or a demonstrated path beyond the reported refcount failure.
Researcher notes
The trigger involves SMC fallback replacing TCP callbacks, leaving sk_user_data pointing to an SMC socket before shutdown reaches sk_psock_get(). The fix adds explicit pointer tagging to prevent type mismatch. Although CVSS assigns high confidentiality, integrity, and availability impacts, the supplied technical evidence directly documents refcount saturation and memory leakage only.
Mitigation direction
Identify running kernel versions and distribution patch levels on Linux systems.
Apply the vendor-supported kernel update containing the referenced stable fix.
Prioritize multi-user systems where untrusted users can execute local processes.
If updates are unavailable, consult distribution guidance for supported mitigations; none are specified in the supplied sources.
Validation and detection
Compare installed kernel builds with distribution advisories and the CVE's fixed commits.
Confirm updated kernels include the SK_USER_DATA_PSOCK tagging change and its PTRMASK dependency.
Reboot into the updated kernel and verify the active version, not merely the installed package.
Monitor kernel logs for refcount saturation warnings involving sk_psock_get or tls_data_ready.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-49979 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
4Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.