CVE-2022-3566 is a race condition in the Linux kernel TCP subsystem involving concurrent access to icsk->icsk_af_ops. A low-privileged attacker with adjacent-network access could exploit the flaw to disclose internal kernel or Internet Protocol information and potentially affect system confidentiality, integrity, and availability. Red Hat rates the issue Moderate at CVSS 4.6, while the NVD score is 7.1.
Red Hat released fixed kernel and real-time kernel packages for affected Red Hat Enterprise Linux 8 and 9 deployments, including RHEL 8.6 Extended Update Support and Red Hat Virtualization 4 on RHEL 8. RHEL 6 and 7 are outside support scope, and Red Hat identified no qualifying workaround; organizations should upgrade affected systems to supported fixed kernel packages. The issue reflects CWE-366, where unsynchronized concurrent access to shared resources can leave data or execution state invalid or unexpected.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:2951 for RHEL 8 kernel packages and RHSA-2023:2736 for RHEL 8 kernel-rt packages to fix CVE-2022-3566.
Red Hat released RHSA-2023:2458 for RHEL 9 kernel packages and RHSA-2023:2148 for RHEL 9 kernel-rt packages to address CVE-2022-3566.
Red Hat released RHSA-2024:0724 with fixed kernel packages for RHEL 8.6 Extended Update Support and Red Hat Virtualization 4 for RHEL 8.
CVE-2022-3566 was identified in the Linux kernel TCP subsystem as a CWE-366 data race involving access to icsk->icsk_af_ops on a do_ipv6_setsockopt-related code path. Exploitation by a low-privileged adjacent-network attacker could disclose kernel or IP information and affect confidentiality, integrity, and availability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.