CVE-2022-49289
Published: Feb 26, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: uaccess: fix integer overflow on access_ok() Three architectures check the end of a user access against the address limit without taking a possible overflow into account. Passing a negative length or another overflow in here returns success when it should not. Use the most common correct implementation here, which optimizes for a constant 'size' argument, and turns the common case into a single comparison.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 7567746e1c0d66ac0ef8a9d8816ca694462c7370 - < e65d28d4e9bf90a35ba79c06661a572a38391decaffected 7567746e1c0d66ac0ef8a9d8816ca694462c7370 - < 99801e2f457824955da4aadaa035913a6dede03aaffected 7567746e1c0d66ac0ef8a9d8816ca694462c7370 - < a1ad747fc1a0e06d1bf26b996ee8a56b5c8d02d8affected 7567746e1c0d66ac0ef8a9d8816ca694462c7370 - < 222ca305c9fd39e5ed8104da25c09b2b79a516a8 |
Linux | Linux | affected 3.2unaffected 0 - < 3.2unaffected 5.15.32 - <= 5.15.*unaffected 5.16.18 - <= 5.16.*unaffected 5.17.1 - <= 5.17.*+1 more versions |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now