cbcvebase.
CVE-2022-49710
published 2025-02-26

CVE-2022-49710: In the Linux kernel, the following vulnerability has been resolved: dm mirror log: round up region bitmap size to BITS_PER_LONG The code in dm-log rounds up…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.3th percentile
In the Linux kernel, the following vulnerability has been resolved: dm mirror log: round up region bitmap size to BITS_PER_LONG The code in dm-log rounds up bitset_size to 32 bits. It then uses find_next_zero_bit_le on the allocated region. find_next_zero_bit_le accesses the bitmap using unsigned long pointers. So, on 64-bit architectures, it may access 4 bytes beyond the allocated size. Fix this bug by rounding up bitset_size to BITS_PER_LONG. This bug was found by running the lvm2 testsuite with kasan.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 29121bd0b00ebb9524971a583fea4a2f7afe8041 < ae460312875159285cef5bf3dc654593f404a1efae460312875159285cef5bf3dc654593f404a1ef
linuxlinux>= 29121bd0b00ebb9524971a583fea4a2f7afe8041 < ba751f0d25f07aa21ce9b85372a3792bf7969d13ba751f0d25f07aa21ce9b85372a3792bf7969d13
linuxlinux>= 29121bd0b00ebb9524971a583fea4a2f7afe8041 < 0d2209b54f1de0c2f99cab246d4cf2cfe24aaaa90d2209b54f1de0c2f99cab246d4cf2cfe24aaaa9
linuxlinux>= 29121bd0b00ebb9524971a583fea4a2f7afe8041 < 9a02f3275acc628c0d956be771405ced79ac36df9a02f3275acc628c0d956be771405ced79ac36df
linuxlinux>= 29121bd0b00ebb9524971a583fea4a2f7afe8041 < 85e123c27d5cbc22cfdc01de1e2ca1d9003a02d085e123c27d5cbc22cfdc01de1e2ca1d9003a02d0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 2.6.18 < 5.4.2005.4.200
linuxlinux_kernel>= 5.11 < 5.15.495.15.49
linuxlinux_kernel>= 5.16 < 5.18.65.18.6
linuxlinux_kernel>= 5.5 < 5.10.1245.10.124

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.