CVE-2022-49790
published 2025-05-01CVE-2022-49790: In the Linux kernel, the following vulnerability has been resolved: Input: iforce - invert valid length check when fetching device IDs syzbot is reporting…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
Input: iforce - invert valid length check when fetching device IDs
syzbot is reporting uninitialized value at iforce_init_device() [1], for
commit 6ac0aec6b0a6 ("Input: iforce - allow callers supply data buffer
when fetching device IDs") is checking that valid length is shorter than
bytes to read. Since iforce_get_id_packet() stores valid length when
returning 0, the caller needs to check that valid length is longer than or
equals to bytes to read.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.10-1 (bookworm) | linux 6.0.10-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 6ac0aec6b0a651d64eef759fddf17d9145b51033 < 5d53797ce7ce8fb1d95a5bebc5efa9418c4217a3 | 5d53797ce7ce8fb1d95a5bebc5efa9418c4217a3 |
| linux | linux | >= 6ac0aec6b0a651d64eef759fddf17d9145b51033 < 24cc679abbf31477d0cc6106ec83c2fbae6b3cdf | 24cc679abbf31477d0cc6106ec83c2fbae6b3cdf |
| linux | linux | >= 6ac0aec6b0a651d64eef759fddf17d9145b51033 < fdd57c20d4408cac3c3c535c120d244e083406c9 | fdd57c20d4408cac3c3c535c120d244e083406c9 |
| linux | linux | >= 6ac0aec6b0a651d64eef759fddf17d9145b51033 < 6365569d62a75ddf53fb0c2936c16587a365984c | 6365569d62a75ddf53fb0c2936c16587a365984c |
| linux | linux | >= 6ac0aec6b0a651d64eef759fddf17d9145b51033 < b8ebf250997c5fb253582f42bfe98673801ebebd | b8ebf250997c5fb253582f42bfe98673801ebebd |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.10-1 | 6.0.10-1 |
| linux | linux_kernel | >= 0 < 6.0.10-1 | 6.0.10-1 |
| linux | linux_kernel | >= 0 < 6.0.10-1 | 6.0.10-1 |
| linux | linux_kernel | >= 5.11 < 5.15.80 | 5.15.80 |
| linux | linux_kernel | >= 5.16 < 6.0.10 | 6.0.10 |
| linux | linux_kernel | >= 5.3 < 5.4.225 | 5.4.225 |
| linux | linux_kernel | >= 5.5 < 5.10.156 | 5.10.156 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Input: iforce - invert valid length check when fetching device IDs
vendor_redhat·2025-05-01·CVSS 5.5
CVE-2022-49790 [MEDIUM] kernel: Input: iforce - invert valid length check when fetching device IDs
kernel: Input: iforce - invert valid length check when fetching device IDs
In the Linux kernel, the following vulnerability has been resolved:
Input: iforce - invert valid length check when fetching device IDs
syzbot is reporting uninitialized value at iforce_init_device() [1], for
commit 6ac0aec6b0a6 ("Input: iforce - allow callers supply data buffer
when fetching device IDs") is checking that valid length is shorter than
bytes to read. Since iforce_get_id_packet() stores valid length when
returning 0, the caller needs to check that valid length is longer than or
equals to bytes to read.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt
Debian
CVE-2022-49790: linux - In the Linux kernel, the following vulnerability has been resolved: Input: ifor...
vendor_debian·2022·CVSS 5.5
CVE-2022-49790 [MEDIUM] CVE-2022-49790: linux - In the Linux kernel, the following vulnerability has been resolved: Input: ifor...
In the Linux kernel, the following vulnerability has been resolved: Input: iforce - invert valid length check when fetching device IDs syzbot is reporting uninitialized value at iforce_init_device() [1], for commit 6ac0aec6b0a6 ("Input: iforce - allow callers supply data buffer when fetching device IDs") is checking that valid length is shorter than bytes to read. Since iforce_get_id_packet() stores valid length when returning 0, the caller needs to check that valid length is longer than or equals to bytes to read.
Scope: local
bookworm: resolved (fixed in 6.0.10-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: resolved (fixed in 6.0.10-1)
sid: resolved (fixed in 6.0.10-1)
trixie: resolved (fixed in 6.0.10-1)
OSV
CVE-2022-49790: In the Linux kernel, the following vulnerability has been resolved: Input: iforce - invert valid length check when fetching device IDs syzbot is repor
osv·2025-05-01·CVSS 5.5
CVE-2022-49790 [MEDIUM] CVE-2022-49790: In the Linux kernel, the following vulnerability has been resolved: Input: iforce - invert valid length check when fetching device IDs syzbot is repor
In the Linux kernel, the following vulnerability has been resolved: Input: iforce - invert valid length check when fetching device IDs syzbot is reporting uninitialized value at iforce_init_device() [1], for commit 6ac0aec6b0a6 ("Input: iforce - allow callers supply data buffer when fetching device IDs") is checking that valid length is shorter than bytes to read. Since iforce_get_id_packet() stores valid length when returning 0, the caller needs to check that valid length is longer than or equals to bytes to read.
GHSA
GHSA-3x3q-3c9j-4x72: In the Linux kernel, the following vulnerability has been resolved:
Input: iforce - invert valid length check when fetching device IDs
syzbot is rep
ghsa_unreviewed·2025-05-01
CVE-2022-49790 [MEDIUM] CWE-908 GHSA-3x3q-3c9j-4x72: In the Linux kernel, the following vulnerability has been resolved:
Input: iforce - invert valid length check when fetching device IDs
syzbot is rep
In the Linux kernel, the following vulnerability has been resolved:
Input: iforce - invert valid length check when fetching device IDs
syzbot is reporting uninitialized value at iforce_init_device() [1], for
commit 6ac0aec6b0a6 ("Input: iforce - allow callers supply data buffer
when fetching device IDs") is checking that valid length is shorter than
bytes to read. Since iforce_get_id_packet() stores valid length when
returning 0, the caller needs to check that valid length is longer than or
equals to bytes to read.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/24cc679abbf31477d0cc6106ec83c2fbae6b3cdfhttps://git.kernel.org/stable/c/5d53797ce7ce8fb1d95a5bebc5efa9418c4217a3https://git.kernel.org/stable/c/6365569d62a75ddf53fb0c2936c16587a365984chttps://git.kernel.org/stable/c/b8ebf250997c5fb253582f42bfe98673801ebebdhttps://git.kernel.org/stable/c/fdd57c20d4408cac3c3c535c120d244e083406c9
2025-05-01
Published