PT-2025-8217 · Linux+2 · Linux Kernel+2

David Laight

·

Published

2022-01-01

·

Updated

2026-03-14

·

CVE-2022-49289

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to an integer overflow in the access ok() function, which is used to check user access. Specifically, three architectures do not account for a possible overflow when checking the end of a user access against the address limit. This can lead to incorrect results when passing a negative length or another overflow. The problem arises from the lack of proper overflow handling, which can cause the function to return success when it should not.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03930
CVE-2022-49289

Affected Products

Astra Linux
Debian
Linux Kernel