CVE-2022-49289

Summary

In the Linux kernel, the following vulnerability has been resolved:

uaccess: fix integer overflow on access_ok()

Three architectures check the end of a user access against the address limit without taking a possible overflow into account. Passing a negative length or another overflow in here returns success when it should not.

Use the most common correct implementation here, which optimizes for a constant 'size' argument, and turns the common case into a single comparison.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux7567746e1c0d66ac0ef8a9d8816ca694462c7370 < e65d28d4e9bf90a35ba79c06661a572a38391decaffected
LinuxLinux7567746e1c0d66ac0ef8a9d8816ca694462c7370 < 99801e2f457824955da4aadaa035913a6dede03aaffected
LinuxLinux7567746e1c0d66ac0ef8a9d8816ca694462c7370 < a1ad747fc1a0e06d1bf26b996ee8a56b5c8d02d8affected
LinuxLinux7567746e1c0d66ac0ef8a9d8816ca694462c7370 < 222ca305c9fd39e5ed8104da25c09b2b79a516a8affected
LinuxLinux3.2affected
LinuxLinux0 < 3.2unaffected
LinuxLinux5.15.32 <= 5.15.*unaffected
LinuxLinux5.16.18 <= 5.16.*unaffected
LinuxLinux5.17.1 <= 5.17.*unaffected
LinuxLinux5.18 <= *unaffected

Weaknesses

References