PT-2025-7986 · Linux+7 · Linux Kernel+7

Harshit Mogalapalli

·

Published

2022-04-13

·

Updated

2025-09-29

·

CVE-2022-49058

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A potential buffer overflow issue has been identified in the Linux kernel, specifically in the handling of symlinks by the cifs module. The problem arises because the link len value, which is obtained from sscanf(), is marked as untrusted by Smatch. This could lead to a buffer overflow when link len exceeds the size of the link str buffer. A check has been added to ensure link len does not exceed the size of the link str buffer.
Recommendations For the Linux kernel, apply the patch that adds a check to ensure link len is not larger than the size of the link str buffer to prevent potential buffer overflow issues.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:11298
ALSA-2025:11299
ALSA-2025_11298
ALSA-2025_11299
ALSA-2025_16880
BDU:2025-06036
CESA-2025_11298
CESA-2025_11299
CVE-2022-49058
INFSA-2025_11298
INFSA-2025_11299
OPENSUSE-SU-2025_1263-1
RHSA-2023:2458
RHSA-2023_2458
RHSA-2025:11298
RHSA-2025:11299
RHSA-2025:11570
RHSA-2025:12238
RHSA-2025:12623
RHSA-2025:13029
RHSA-2025:13030
RHSA-2025:13061
RHSA-2025_11298
RHSA-2025_11299
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1
SUSE-SU-2025_1293-1

Affected Products

Almalinux
Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse