CVE Database
/

CVE-2022-49289

Back to search

CVE-2022-49289

Published: Feb 26, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: uaccess: fix integer overflow on access_ok() Three architectures check the end of a user access against the address limit without taking a possible overflow into account. Passing a negative length or another overflow in here returns success when it should not. Use the most common correct implementation here, which optimizes for a constant 'size' argument, and turns the common case into a single comparison.

VendorProductVersions

Linux

Linux

affected
7567746e1c0d66ac0ef8a9d8816ca694462c7370 - < e65d28d4e9bf90a35ba79c06661a572a38391dec
affected
7567746e1c0d66ac0ef8a9d8816ca694462c7370 - < 99801e2f457824955da4aadaa035913a6dede03a
affected
7567746e1c0d66ac0ef8a9d8816ca694462c7370 - < a1ad747fc1a0e06d1bf26b996ee8a56b5c8d02d8
affected
7567746e1c0d66ac0ef8a9d8816ca694462c7370 - < 222ca305c9fd39e5ed8104da25c09b2b79a516a8

Linux

Linux

affected
3.2
unaffected
0 - < 3.2
unaffected
5.15.32 - <= 5.15.*
unaffected
5.16.18 - <= 5.16.*
unaffected
5.17.1 - <= 5.17.*

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now