#VU104787 Integer underflow in Linux kernel - CVE-2022-49280
Published: February 26, 2025 / Updated: May 11, 2025
Vulnerability identifier: #VU104787
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-49280
CWE-ID: CWE-191
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to integer underflow within the nfsd_proc_write() function in fs/nfsd/nfsproc.c. A local user can execute arbitrary code.
Remediation
Install update from vendor's website.
External links
- https://git.kernel.org/stable/c/184416d4b98509fb4c3d8fc3d6dc1437896cc159
- https://git.kernel.org/stable/c/1a33e0de60feda402d05ac8a6cf409c19ea3e0b3
- https://git.kernel.org/stable/c/2764af8ce0bf03cc43ee4a11897cab96bde6caae
- https://git.kernel.org/stable/c/413d8fefafe531a9442bb623e3fe292a38f88d65
- https://git.kernel.org/stable/c/438068f4912183a59fcb6b7496a06437f7fd4e2b
- https://git.kernel.org/stable/c/614a61e1592051cc42d3c38f899c9f7bdaad8a1d
- https://git.kernel.org/stable/c/65e21cc042f4c1518c8c55283f53bc725b78419d
- https://git.kernel.org/stable/c/85259340fc9bd54e3d567b41b881ecb4d0055da1
- https://git.kernel.org/stable/c/9f0f048c1bfa7867d565a95fd8c28f4484ba1043
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.238