cbcvebase.
CVE-2022-49058
published 2025-02-26

CVE-2022-49058: In the Linux kernel, the following vulnerability has been resolved: cifs: potential buffer overflow in handling symlinks Smatch printed a warning…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.32%
24.6th percentile
In the Linux kernel, the following vulnerability has been resolved: cifs: potential buffer overflow in handling symlinks Smatch printed a warning: arch/x86/crypto/poly1305_glue.c:198 poly1305_update_arch() error: __memcpy() 'dctx->buf' too small (16 vs u32max) It's caused because Smatch marks 'link_len' as untrusted since it comes from sscanf(). Add a check to ensure that 'link_len' is not larger than the size of the 'link_str' buffer.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.6-1 (bookworm)linux 5.17.6-1 (bookworm)
linuxlinux
linuxlinux>= c69c1b6eaea1b3e1eecf7ad2fba0208ac4a11131 < 3e582749e742e662a8e9bb37cffac62dccaaa1e23e582749e742e662a8e9bb37cffac62dccaaa1e2
linuxlinux>= c69c1b6eaea1b3e1eecf7ad2fba0208ac4a11131 < 1316c28569a80ab3596eeab05bf5e01991e7e7391316c28569a80ab3596eeab05bf5e01991e7e739
linuxlinux>= c69c1b6eaea1b3e1eecf7ad2fba0208ac4a11131 < eb5f51756944735ac70cd8bb38637cc202e29c91eb5f51756944735ac70cd8bb38637cc202e29c91
linuxlinux>= c69c1b6eaea1b3e1eecf7ad2fba0208ac4a11131 < 22d658c6c5affed10c8907e67160cef0b6c9218622d658c6c5affed10c8907e67160cef0b6c92186
linuxlinux>= c69c1b6eaea1b3e1eecf7ad2fba0208ac4a11131 < 4e166a41180be2f1e66bbb6d46448e80a9a5ec054e166a41180be2f1e66bbb6d46448e80a9a5ec05
linuxlinux>= c69c1b6eaea1b3e1eecf7ad2fba0208ac4a11131 < 9901b07ba42b39266b34a888e48d7306fd707bee9901b07ba42b39266b34a888e48d7306fd707bee
linuxlinux>= c69c1b6eaea1b3e1eecf7ad2fba0208ac4a11131 < 515e7ba11ef043d6febe69389949c8ef5f25e9d0515e7ba11ef043d6febe69389949c8ef5f25e9d0
linuxlinux>= c69c1b6eaea1b3e1eecf7ad2fba0208ac4a11131 < 64c4a37ac04eeb43c42d272f6e6c8c12bfcf430464c4a37ac04eeb43c42d272f6e6c8c12bfcf4304
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.6-15.17.6-1
linuxlinux_kernel>= 0 < 5.17.6-15.17.6-1
linuxlinux_kernel>= 0 < 5.17.6-15.17.6-1
linuxlinux_kernel>= 2.6.37 < 4.9.3114.9.311
linuxlinux_kernel>= 4.10 < 4.14.2764.14.276
linuxlinux_kernel>= 4.15 < 4.19.2394.19.239
linuxlinux_kernel>= 4.20 < 5.4.1905.4.190
linuxlinux_kernel>= 5.11 < 5.15.355.15.35
linuxlinux_kernel>= 5.16 < 5.17.45.17.4
linuxlinux_kernel>= 5.5 < 5.10.1125.10.112

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.