🛡️ CVE-2022-49799 — kernel

🟠 CVSS 7.1 — High ✅ No Known Exploit NVD
7.1
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

tracing: Fix wild-memory-access in register_synth_event()

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix wild-memory-access in register_synth_event()

In register_synth_event(), if set_synth_event_print_fmt() failed, then

both trace_remove_event_call() and unregister_trace_event() will be

called, which means the trace_event_call will call

__unregister_trace_event() twice. As the result, the second unregister

will causes the wild-memory-access.

register_synth_event

set_synth_event_print_fmt failed

trace_remove_event_call

event_remove

if call->event.funcs then

__unregister_trace_event (first call)

unregister_trace_event

__unregister_trace_event (second call)

Fix the bug by avoiding to call the second __unregister_trace_event() by

checking if the first one is called.

general protection fault, probably for non-canonical address

0xfbd59c0000000024: 0000 [#1] SMP KASAN PTI

KASAN: maybe wild-memory-access in range

[0xdead000000000120-0xdead000000000127]

CPU: 0 PID: 3807 Comm: modprobe Not tainted

6.1.0-rc1-00186-g76f33a7eedb4 #299

Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS

rel-1.15.0-0-g2dd4b9b3f840-prebuilt.qemu.org 04/01/2014

RIP: 0010:unregister_trace_event+0x6e/0x280

Code: 00 fc ff df 4c 89 ea 48 c1 ea 03 80 3c 02 00 0f 85 0e 02 00 00 48

b8 00 00 00 00 00 fc ff df 4c 8b 63 08 4c 89 e2 48 c1 ea 03 <80> 3c 02

00 0f 85 e2 01 00 00 49 89 2c 24 48 85 ed 74 28 e8 7a 9b

RSP: 0018:ffff88810413f370 EFLAGS: 00010a06

RAX: dffffc0000000000 RBX: ffff888105d050b0 RCX: 0000000000000000

RDX: 1bd5a00000000024 RSI: ffff888119e276e0 RDI: ffffffff835a8b20

RBP: dead000000000100 R08: 0000000000000000 R09: fffffbfff0913481

R10: ffffffff8489a407 R11: fffffbfff0913480 R12: dead000000000122

R13: ffff888105d050b8 R14: 0000000000000000 R15: ffff888105d05028

FS: 00007f7823e8d540(0000) GS:ffff888119e00000(0000)

knlGS:0000000000000000

CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033

CR2: 00007f7823e7ebec CR3: 000000010a058002 CR4: 0000000000330ef0

DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000

DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400

Call Trace:

<TASK>

__create_synth_event+0x1e37/0x1eb0

create_or_delete_synth_event+0x110/0x250

synth_event_run_command+0x2f/0x110

test_gen_synth_cmd+0x170/0x2eb [synth_event_gen_test]

synth_event_gen_test_init+0x76/0x9bc [synth_event_gen_test]

do_one_initcall+0xdb/0x480

do_init_module+0x1cf/0x680

load_module+0x6a50/0x70a0

__do_sys_finit_module+0x12f/0x1c0

do_syscall_64+0x3f/0x90

entry_SYSCALL_64_after_hwframe+0x63/0xcd

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity none, availability high.

Affected software

CVE-2022-49799 is recorded against 2 packages.

  • kernel (from 5.16.0 up to 6.0.10)
  • linux-kernel

Timeline and source

Published on 1 May 2025 and last revised on 15 July 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2022-49799 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity High
CVSS Score 7.1
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2025-05-01
Updated 2026-08-12
Modified 2026-07-15

Affected Packages

Software From version Fixed in
kernel 5.16.0 6.0.10
linux-kernel

Similar Threats

Site Security Check

Is kernel part of your stack?

CVE-2022-49799 is rated CVSS 7.1 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2022