cbcvebase.
CVE-2022-49279
published 2025-02-26

CVE-2022-49279: In the Linux kernel, the following vulnerability has been resolved: NFSD: prevent integer overflow on 32 bit systems On a 32 bit system, the "len * sizeof(*p)"…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.60%
45.5th percentile
In the Linux kernel, the following vulnerability has been resolved: NFSD: prevent integer overflow on 32 bit systems On a 32 bit system, the "len * sizeof(*p)" operation can have an integer overflow.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 37c88763def8474bc0972fbd1adb0d21670104b7 < 3a2789e8ccb4a3e2a631f6817a2d3bb98b8c4fd83a2789e8ccb4a3e2a631f6817a2d3bb98b8c4fd8
linuxlinux>= 37c88763def8474bc0972fbd1adb0d21670104b7 < ce1aa09cc14ed625104acc2d487bd92b9a88efe2ce1aa09cc14ed625104acc2d487bd92b9a88efe2
linuxlinux>= 37c88763def8474bc0972fbd1adb0d21670104b7 < 7af164fa2f1abc577d357d22d83a2f3490875d7e7af164fa2f1abc577d357d22d83a2f3490875d7e
linuxlinux>= 37c88763def8474bc0972fbd1adb0d21670104b7 < 303cd6173dce0a28d26526c77814eb90a41bd898303cd6173dce0a28d26526c77814eb90a41bd898
linuxlinux>= 37c88763def8474bc0972fbd1adb0d21670104b7 < 79b1c54fc6ce09ee0d5fe088bb3de26ae2150e3c79b1c54fc6ce09ee0d5fe088bb3de26ae2150e3c
linuxlinux>= 37c88763def8474bc0972fbd1adb0d21670104b7 < e4195d27306ea468a6dc3a27af6f586709951229e4195d27306ea468a6dc3a27af6f586709951229
linuxlinux>= 37c88763def8474bc0972fbd1adb0d21670104b7 < 23a9dbbe0faf124fc4c139615633b9d12a3a89ef23a9dbbe0faf124fc4c139615633b9d12a3a89ef
linuxlinux_kernel< 4.19.2384.19.238
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 4.20 < 5.4.1895.4.189
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2
linuxlinux_kernel>= 5.5 < 5.10.1105.10.110

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.