cbcvebase.
CVE-2022-49643
published 2025-02-26

CVE-2022-49643: In the Linux kernel, the following vulnerability has been resolved: ima: Fix a potential integer overflow in ima_appraise_measurement When the ima-modsig is…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ima: Fix a potential integer overflow in ima_appraise_measurement When the ima-modsig is enabled, the rc passed to evm_verifyxattr() may be negative, which may cause the integer overflow problem.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 39b07096364a42c516415d5f841069e885234e61 < 388f3df7c3c8b7f2a32b9ae0a9b2f9f6ad3b1b77388f3df7c3c8b7f2a32b9ae0a9b2f9f6ad3b1b77
linuxlinux>= 39b07096364a42c516415d5f841069e885234e61 < 831e190175f10652be93b08436cc7bf2e62e4bb6831e190175f10652be93b08436cc7bf2e62e4bb6
linuxlinux>= 39b07096364a42c516415d5f841069e885234e61 < c8d5d81940938b5f6c0f495ca9538e7740416f30c8d5d81940938b5f6c0f495ca9538e7740416f30
linuxlinux>= 39b07096364a42c516415d5f841069e885234e61 < 640cea4c2839a821adfbb703b590a5928abe9286640cea4c2839a821adfbb703b590a5928abe9286
linuxlinux>= 39b07096364a42c516415d5f841069e885234e61 < d2ee2cfc4aa85ff6a2a3b198a3a524ec54e3d999d2ee2cfc4aa85ff6a2a3b198a3a524ec54e3d999
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 5.11 < 5.15.565.15.56
linuxlinux_kernel>= 5.16 < 5.18.135.18.13
linuxlinux_kernel>= 5.4 < 5.4.2075.4.207
linuxlinux_kernel>= 5.5 < 5.10.1325.10.132

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.