CVE-2022-49785
published 2025-05-01CVE-2022-49785: In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Add overflow check in sgx_validate_offset_length() sgx_validate_offset_length()…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
x86/sgx: Add overflow check in sgx_validate_offset_length()
sgx_validate_offset_length() function verifies "offset" and "length"
arguments provided by userspace, but was missing an overflow check on
their addition. Add it.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.10-1 (bookworm) | linux 6.0.10-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= c6d26d370767fa227fc44b98a8bdad112efdf563 < 5277e3d633a5d4157987f4aff068caa55e36db19 | 5277e3d633a5d4157987f4aff068caa55e36db19 |
| linux | linux | >= c6d26d370767fa227fc44b98a8bdad112efdf563 < 3b1c10fb754b0b67165e3f055a4208e5ba26dc89 | 3b1c10fb754b0b67165e3f055a4208e5ba26dc89 |
| linux | linux | >= c6d26d370767fa227fc44b98a8bdad112efdf563 < f0861f49bd946ff94fce4f82509c45e167f63690 | f0861f49bd946ff94fce4f82509c45e167f63690 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.0.10-1 | 6.0.10-1 |
| linux | linux_kernel | >= 0 < 6.0.10-1 | 6.0.10-1 |
| linux | linux_kernel | >= 0 < 6.0.10-1 | 6.0.10-1 |
| linux | linux_kernel | >= 5.11 < 5.15.81 | 5.15.81 |
| linux | linux_kernel | >= 5.16 < 6.0.10 | 6.0.10 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-49785: In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Add overflow check in sgx_validate_offset_length() sgx_validate_offset_le
osv·2025-05-01·CVSS 5.5
CVE-2022-49785 [MEDIUM] CVE-2022-49785: In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Add overflow check in sgx_validate_offset_length() sgx_validate_offset_le
In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Add overflow check in sgx_validate_offset_length() sgx_validate_offset_length() function verifies "offset" and "length" arguments provided by userspace, but was missing an overflow check on their addition. Add it.
GHSA
GHSA-rpgj-4c7v-rffq: In the Linux kernel, the following vulnerability has been resolved:
x86/sgx: Add overflow check in sgx_validate_offset_length()
sgx_validate_offset_
ghsa_unreviewed·2025-05-01
CVE-2022-49785 [MEDIUM] GHSA-rpgj-4c7v-rffq: In the Linux kernel, the following vulnerability has been resolved:
x86/sgx: Add overflow check in sgx_validate_offset_length()
sgx_validate_offset_
In the Linux kernel, the following vulnerability has been resolved:
x86/sgx: Add overflow check in sgx_validate_offset_length()
sgx_validate_offset_length() function verifies "offset" and "length"
arguments provided by userspace, but was missing an overflow check on
their addition. Add it.
Red Hat
kernel: x86/sgx: Add overflow check in sgx_validate_offset_length()
vendor_redhat·2025-05-01·CVSS 5.5
CVE-2022-49785 [MEDIUM] kernel: x86/sgx: Add overflow check in sgx_validate_offset_length()
kernel: x86/sgx: Add overflow check in sgx_validate_offset_length()
In the Linux kernel, the following vulnerability has been resolved:
x86/sgx: Add overflow check in sgx_validate_offset_length()
sgx_validate_offset_length() function verifies "offset" and "length"
arguments provided by userspace, but was missing an overflow check on
their addition. Add it.
Statement: The vulnerability in sgx_validate_offset_length() allows a local attacker to bypass bounds checks via integer overflow when providing crafted offset and length values to the SGX_IOC_ENCLAVE_ADD_PAGES ioctl.
The issue requires local access and low privileges, as the SGX device is typically accessible to unprivileged users.
However, it only affects systems with Intel SGX support enabled in the kernel, and exploitation can lead
Debian
CVE-2022-49785: linux - In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Ad...
vendor_debian·2022·CVSS 5.5
CVE-2022-49785 [MEDIUM] CVE-2022-49785: linux - In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Ad...
In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Add overflow check in sgx_validate_offset_length() sgx_validate_offset_length() function verifies "offset" and "length" arguments provided by userspace, but was missing an overflow check on their addition. Add it.
Scope: local
bookworm: resolved (fixed in 6.0.10-1)
bullseye: resolved
forky: resolved (fixed in 6.0.10-1)
sid: resolved (fixed in 6.0.10-1)
trixie: resolved (fixed in 6.0.10-1)
No detection rules found.
No public exploits indexed.
2025-05-01
Published