CVE-2022-50764
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/12/2025
Last modified:
29/12/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ipv6/sit: use DEV_STATS_INC() to avoid data-races<br />
<br />
syzbot/KCSAN reported that multiple cpus are updating dev->stats.tx_error<br />
concurrently.<br />
<br />
This is because sit tunnels are NETIF_F_LLTX, meaning their ndo_start_xmit()<br />
is not protected by a spinlock.<br />
<br />
While original KCSAN report was about tx path, rx path has the same issue.



