SB20250226611 - Integer overflow in Linux kernel include asm
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow (CVE-ID: CVE-2022-49289)
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to integer overflow within the arch/microblaze/include/asm/uaccess.h, arch/csky/include/asm/uaccess.h. A local user can execute arbitrary code.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/222ca305c9fd39e5ed8104da25c09b2b79a516a8
- https://git.kernel.org/stable/c/99801e2f457824955da4aadaa035913a6dede03a
- https://git.kernel.org/stable/c/a1ad747fc1a0e06d1bf26b996ee8a56b5c8d02d8
- https://git.kernel.org/stable/c/e65d28d4e9bf90a35ba79c06661a572a38391dec
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.32