CVE-2022-49180
published 2025-02-26CVE-2022-49180: In the Linux kernel, the following vulnerability has been resolved: LSM: general protection fault in legacy_parse_param The usual LSM hook "bail on fail"…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
LSM: general protection fault in legacy_parse_param
The usual LSM hook "bail on fail" scheme doesn't work for cases where
a security module may return an error code indicating that it does not
recognize an input. In this particular case Smack sees a mount option
that it recognizes, and returns 0. A call to a BPF hook follows, which
returns -ENOPARAM, which confuses the caller because Smack has processed
its data.
The SELinux hook incorrectly returns 1 on success. There was a time
when this was correct, however the current expectation is that it
return 0 on success. This is repaired.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.17.3-1 (bookworm) | linux 5.17.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= da2441fdffbf7602da702aea5bd95ca4dc3d63fc < ddcdda888e14ca451b3ee83d11b65b2a9c8e783b | ddcdda888e14ca451b3ee83d11b65b2a9c8e783b |
| linux | linux | >= da2441fdffbf7602da702aea5bd95ca4dc3d63fc < 2784604c8c6fc523248f8f80a421c313a9d790b7 | 2784604c8c6fc523248f8f80a421c313a9d790b7 |
| linux | linux | >= da2441fdffbf7602da702aea5bd95ca4dc3d63fc < f3f93a1aaafc3032e0a9655fb43deccfb3e953a3 | f3f93a1aaafc3032e0a9655fb43deccfb3e953a3 |
| linux | linux | >= da2441fdffbf7602da702aea5bd95ca4dc3d63fc < 00fc07fa0b4a004711b6e1a944f0d2e46f7093b7 | 00fc07fa0b4a004711b6e1a944f0d2e46f7093b7 |
| linux | linux | >= da2441fdffbf7602da702aea5bd95ca4dc3d63fc < cadae7c5e477aaafcba819b8e4a3d1c1a1503b62 | cadae7c5e477aaafcba819b8e4a3d1c1a1503b62 |
| linux | linux | >= da2441fdffbf7602da702aea5bd95ca4dc3d63fc < ecff30575b5ad0eda149aadad247b7f75411fd47 | ecff30575b5ad0eda149aadad247b7f75411fd47 |
| linux | linux_kernel | < 5.4.189 | 5.4.189 |
| linux | linux_kernel | >= 0 < 5.10.113-1 | 5.10.113-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 5.11 < 5.15.33 | 5.15.33 |
| linux | linux_kernel | >= 5.16 < 5.16.19 | 5.16.19 |
| linux | linux_kernel | >= 5.17 < 5.17.2 | 5.17.2 |
| linux | linux_kernel | >= 5.5 < 5.10.110 | 5.10.110 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pqwr-48cq-xrw8: In the Linux kernel, the following vulnerability has been resolved:
LSM: general protection fault in legacy_parse_param
The usual LSM hook "bail on
ghsa_unreviewed·2025-10-22
CVE-2022-49180 [MEDIUM] GHSA-pqwr-48cq-xrw8: In the Linux kernel, the following vulnerability has been resolved:
LSM: general protection fault in legacy_parse_param
The usual LSM hook "bail on
In the Linux kernel, the following vulnerability has been resolved:
LSM: general protection fault in legacy_parse_param
The usual LSM hook "bail on fail" scheme doesn't work for cases where
a security module may return an error code indicating that it does not
recognize an input. In this particular case Smack sees a mount option
that it recognizes, and returns 0. A call to a BPF hook follows, which
returns -ENOPARAM, which confuses the caller because Smack has processed
its data.
The SELinux hook incorrectly returns 1 on success. There was a time
when this was correct, however the current expectation is that it
return 0 on success. This is repaired.
OSV
CVE-2022-49180: In the Linux kernel, the following vulnerability has been resolved: LSM: general protection fault in legacy_parse_param The usual LSM hook "bail on fa
osv·2025-02-26·CVSS 5.5
CVE-2022-49180 [MEDIUM] CVE-2022-49180: In the Linux kernel, the following vulnerability has been resolved: LSM: general protection fault in legacy_parse_param The usual LSM hook "bail on fa
In the Linux kernel, the following vulnerability has been resolved: LSM: general protection fault in legacy_parse_param The usual LSM hook "bail on fail" scheme doesn't work for cases where a security module may return an error code indicating that it does not recognize an input. In this particular case Smack sees a mount option that it recognizes, and returns 0. A call to a BPF hook follows, which returns -ENOPARAM, which confuses the caller because Smack has processed its data. The SELinux hook incorrectly returns 1 on success. There was a time when this was correct, however the current expectation is that it return 0 on success. This is repaired.
Red Hat
kernel: LSM: general protection fault in legacy_parse_param
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49180 [MEDIUM] CWE-807 kernel: LSM: general protection fault in legacy_parse_param
kernel: LSM: general protection fault in legacy_parse_param
In the Linux kernel, the following vulnerability has been resolved:
LSM: general protection fault in legacy_parse_param
The usual LSM hook "bail on fail" scheme doesn't work for cases where
a security module may return an error code indicating that it does not
recognize an input. In this particular case Smack sees a mount option
that it recognizes, and returns 0. A call to a BPF hook follows, which
returns -ENOPARAM, which confuses the caller because Smack has processed
its data.
The SELinux hook incorrectly returns 1 on success. There was a time
when this was correct, however the current expectation is that it
return 0 on success. This is repaired.
Mitigation: Mitigation for this issue is either not available or the currently a
Debian
CVE-2022-49180: linux - In the Linux kernel, the following vulnerability has been resolved: LSM: genera...
vendor_debian·2022·CVSS 5.5
CVE-2022-49180 [MEDIUM] CVE-2022-49180: linux - In the Linux kernel, the following vulnerability has been resolved: LSM: genera...
In the Linux kernel, the following vulnerability has been resolved: LSM: general protection fault in legacy_parse_param The usual LSM hook "bail on fail" scheme doesn't work for cases where a security module may return an error code indicating that it does not recognize an input. In this particular case Smack sees a mount option that it recognizes, and returns 0. A call to a BPF hook follows, which returns -ENOPARAM, which confuses the caller because Smack has processed its data. The SELinux hook incorrectly returns 1 on success. There was a time when this was correct, however the current expectation is that it return 0 on success. This is repaired.
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.17.3-1)
sid: resolved
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/00fc07fa0b4a004711b6e1a944f0d2e46f7093b7https://git.kernel.org/stable/c/2784604c8c6fc523248f8f80a421c313a9d790b7https://git.kernel.org/stable/c/cadae7c5e477aaafcba819b8e4a3d1c1a1503b62https://git.kernel.org/stable/c/ddcdda888e14ca451b3ee83d11b65b2a9c8e783bhttps://git.kernel.org/stable/c/ecff30575b5ad0eda149aadad247b7f75411fd47https://git.kernel.org/stable/c/f3f93a1aaafc3032e0a9655fb43deccfb3e953a3
2025-02-26
Published