Vulnerability record · CVE-2022-3521 · published 16 October 2022
CVE-2022-3521: Linux kernel race condition vulnerability
Linux · Linux Kernel
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VDB-211018 is the identifier assigned to this vulnerability.
Description
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VDB-211018 is the identifier assigned to this vulnerability.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ec7eede369fe5b0d085ac51fdbb95184f87bfc6c | Mailing ListPatch |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html | Mailing ListThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00034.html | Mailing ListThird Party Advisory |
| https://vuldb.com/?id.211018 | Permissions RequiredThird Party Advisory |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ec7eede369fe5b0d085ac51fdbb95184f87bfc6c | Mailing ListPatch |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html | Mailing ListThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00034.html | Mailing ListThird Party Advisory |
| https://vuldb.com/?id.211018 | Permissions RequiredThird Party Advisory |
Track CVE-2022-3521 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-3521), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.