cbcvebase.
CVE-2022-49727
published 2025-02-26

CVE-2022-49727: In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix signed integer overflow in l2tp_ip6_sendmsg When len >= INT_MAX - transhdrlen…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix signed integer overflow in l2tp_ip6_sendmsg When len >= INT_MAX - transhdrlen, ulen = len + transhdrlen will be overflow. To fix, we can follow what udpv6 does and subtract the transhdrlen from the max.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= a32e0eec7042b21ccb52896cf715e3e2641fed93 < 2cf73c7cb6125083408d77f43d0e84d86aed00002cf73c7cb6125083408d77f43d0e84d86aed0000
linuxlinux>= a32e0eec7042b21ccb52896cf715e3e2641fed93 < 0e818d433fc2718fe4da044ffca7431812a7e04e0e818d433fc2718fe4da044ffca7431812a7e04e
linuxlinux>= a32e0eec7042b21ccb52896cf715e3e2641fed93 < 6c4e3486d21173d60925ef52e512cae727b43d306c4e3486d21173d60925ef52e512cae727b43d30
linuxlinux>= a32e0eec7042b21ccb52896cf715e3e2641fed93 < 2f42389d270f2304c8855b0b63498a5a4d0c053d2f42389d270f2304c8855b0b63498a5a4d0c053d
linuxlinux>= a32e0eec7042b21ccb52896cf715e3e2641fed93 < b8879ca1fd7348b4d5db7db86dcb97f60c73d751b8879ca1fd7348b4d5db7db86dcb97f60c73d751
linuxlinux>= a32e0eec7042b21ccb52896cf715e3e2641fed93 < 27a37755ceb401111ded76810359d3adc4b268a127a37755ceb401111ded76810359d3adc4b268a1
linuxlinux>= a32e0eec7042b21ccb52896cf715e3e2641fed93 < 034246122f5c5e2e2a0b9fe04e24517920e9beb1034246122f5c5e2e2a0b9fe04e24517920e9beb1
linuxlinux>= a32e0eec7042b21ccb52896cf715e3e2641fed93 < f638a84afef3dfe10554c51820c16e39a278c915f638a84afef3dfe10554c51820c16e39a278c915
linuxlinux_kernel< 4.9.3204.9.320
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 4.10 < 4.14.2854.14.285
linuxlinux_kernel>= 4.15 < 4.19.2494.19.249
linuxlinux_kernel>= 4.20 < 5.4.2005.4.200
linuxlinux_kernel>= 5.11 < 5.15.495.15.49
linuxlinux_kernel>= 5.16 < 5.18.65.18.6
linuxlinux_kernel>= 5.5 < 5.10.1245.10.124

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.