U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-49325

Change History

New CVE Received from kernel.org 2/26/2025 2:01:09 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

tcp: add accessors to read/set tp->snd_cwnd

We had various bugs over the years with code
breaking the assumption that tp->snd_cwnd is greater
than zero.

Lately, syzbot reported the WARN_ON_ONCE(!tp->prior_cwnd) added
in commit 8b8a321ff72c ("tcp: fix zero cwnd in tcp_cwnd_reduction")
can trigger, and without a repro we would have to spend
considerable time finding the bug.

Instead of complaining too late, we want to catch where
and when tp->snd_cwnd is set to an illegal value.
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/3308676ec525901bf1656014003c443a60730a04
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/40570375356c874b1578e05c1dcc3ff7c1322dbe
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/41e191fe72282e193a7744e2fc1786b23156c9e4
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/5aba0ad44fb4a7fb78c5076c313456de199a3c29