CVE-2022-50265: kcm: annotate data-races around kcm->rx_wait

Published Sep 15, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

kcm: annotate data-races around kcm->rxwait

kcm->rxpsock can be read locklessly in kcmrfree(). Annotate the read and writes accordingly.

syzbot reported:

BUG: KCSAN: data-race in kcmrcvstrparser / kcmrfree

write to 0xffff88810784e3d0 of 1 bytes by task 1823 on cpu 1: reserverxkcm net/kcm/kcmsock.c:283 [inline] kcmrcvstrparser+0x250/0x3a0 net/kcm/kcmsock.c:363 strprecv+0x64c/0xd20 net/strparser/strparser.c:301 strprecv+0x6d/0x80 net/strparser/strparser.c:335 tcpreadsock+0x13e/0x5a0 net/ipv4/tcp.c:1703 strpreadsock net/strparser/strparser.c:358 [inline] dostrpwork net/strparser/strparser.c:406 [inline] strpwork+0xe8/0x180 net/strparser/strparser.c:415 processonework+0x3d3/0x720 kernel/workqueue.c:2289 workerthread+0x618/0xa70 kernel/workqueue.c:2436 kthread+0x1a9/0x1e0 kernel/kthread.c:376 retfromfork+0x1f/0x30 arch/x86/entry/entry64.S:306

read to 0xffff88810784e3d0 of 1 bytes by task 17869 on cpu 0: kcmrfree+0x121/0x220 net/kcm/kcmsock.c:181 skbreleaseheadstate+0x8e/0x160 net/core/skbuff.c:841 skbreleaseall net/core/skbuff.c:852 [inline] kfreeskb net/core/skbuff.c:868 [inline] kfreeskbreason+0x5c/0x260 net/core/skbuff.c:891 kfreeskb include/linux/skbuff.h:1216 [inline] kcmrecvmsg+0x226/0x2b0 net/kcm/kcmsock.c:1161 sysrecvmsg+0x16c/0x2e0 sysrecvmsg net/socket.c:2743 [inline] dorecvmmsg+0x2f1/0x710 net/socket.c:2837 sysrecvmmsg net/socket.c:2916 [inline] dosysrecvmmsg net/socket.c:2939 [inline] sesysrecvmmsg net/socket.c:2932 [inline] x64sysrecvmmsg+0xde/0x160 net/socket.c:2932 dosyscallx64 arch/x86/entry/common.c:50 [inline] dosyscall64+0x2b/0x70 arch/x86/entry/common.c:80 entrySYSCALL64afterhwframe+0x63/0xcd

value changed: 0x01 -> 0x00

Reported by Kernel Concurrency Sanitizer on: CPU: 0 PID: 17869 Comm: syz-executor.2 Not tainted 6.1.0-rc1-syzkaller-00010-gbb1a1146467a-dirty #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/22/2022

Affected Software

10 affected components
Linux Linux kernel
Linux Linux kernel>=4.6<4.9.332
Linux Linux kernel>=4.10<4.14.298
Linux Linux kernel>=4.15<4.19.264
Linux Linux kernel>=4.20<5.4.223
Linux Linux kernel>=5.5<5.10.153
Linux Linux kernel>=5.11<5.15.77
Linux Linux kernel>=5.16<6.0.7
Linux Linux kernel=6.1-rc1
Linux Linux kernel=6.1-rc2

Event History

Sep 15, 2025
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2022-50265?

CVE-2022-50265 has been classified as a moderate severity vulnerability due to the potential for data races in the Linux kernel.

2

How do I fix CVE-2022-50265?

To fix CVE-2022-50265, ensure you update to the latest stable version of the Linux kernel that includes the resolution for this vulnerability.

3

What systems are affected by CVE-2022-50265?

CVE-2022-50265 affects certain versions of the Linux kernel, particularly those related to the kcm component.

4

What are the implications of CVE-2022-50265?

The implications of CVE-2022-50265 include potential data inconsistency and stability issues due to data races in kernel space.

5

How can I determine if my system is vulnerable to CVE-2022-50265?

To determine if your system is vulnerable to CVE-2022-50265, you should check your Linux kernel version against the vulnerability reports and update if necessary.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203