{"schema_version":"1.9.0","id":"CVE-2022-49325","published":"2025-02-26T02:10:48.158Z","modified":"2026-08-12T03:51:26.536136500Z","related":["SUSE-SU-2025:01600-1","SUSE-SU-2025:1176-1","SUSE-SU-2025:1241-1"],"summary":"tcp: add accessors to read/set tp->snd_cwnd","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: add accessors to read/set tp->snd_cwnd\n\nWe had various bugs over the years with code\nbreaking the assumption that tp->snd_cwnd is greater\nthan zero.\n\nLately, syzbot reported the WARN_ON_ONCE(!tp->prior_cwnd) added\nin commit 8b8a321ff72c (\"tcp: fix zero cwnd in tcp_cwnd_reduction\")\ncan trigger, and without a repro we would have to spend\nconsiderable time finding the bug.\n\nInstead of complaining too late, we want to catch where\nand when tp->snd_cwnd is set to an illegal value.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5d424d5a674f782d0659a3b66d951f412901faee"},{"fixed":"3308676ec525901bf1656014003c443a60730a04"},{"fixed":"5aba0ad44fb4a7fb78c5076c313456de199a3c29"},{"fixed":"41e191fe72282e193a7744e2fc1786b23156c9e4"},{"fixed":"40570375356c874b1578e05c1dcc3ff7c1322dbe"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49325.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.17"},{"fixed":"5.15.47"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"5.17.15"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.18.0"},{"fixed":"5.18.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49325.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/3308676ec525901bf1656014003c443a60730a04"},{"type":"WEB","url":"https://git.kernel.org/stable/c/40570375356c874b1578e05c1dcc3ff7c1322dbe"},{"type":"WEB","url":"https://git.kernel.org/stable/c/41e191fe72282e193a7744e2fc1786b23156c9e4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5aba0ad44fb4a7fb78c5076c313456de199a3c29"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49325.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-49325"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49325.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}