Executive Summary



This vulnerability is currently undergoing analysis and not all information is available. Please check back soon to view the completed vulnerability summary
Informations
Name CVE-2022-49122 First vendor Publication 2025-02-26
Vendor Cve Last vendor Modification 2025-02-26

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

dm ioctl: prevent potential spectre v1 gadget

It appears like cmd could be a Spectre v1 gadget as it's supplied by a user and used as an array index. Prevent the contents of kernel memory from being leaked to userspace via speculative execution by using array_index_nospec.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-49122

Sources (Detail)

https://git.kernel.org/stable/c/02cc46f397eb3691c56affbd5073e54f7a82ac32
https://git.kernel.org/stable/c/0320bac5801b31407200227173205d017488f140
https://git.kernel.org/stable/c/44e6cb3ab177faae840bb2c1ebda9a2539876184
https://git.kernel.org/stable/c/58880025e3362024f6d8ea01cb0c7a5df6c84ba6
https://git.kernel.org/stable/c/71c8df33fd777c7628f6fbc09b14e84806c55914
https://git.kernel.org/stable/c/76c94651005f58885facf9c973007f5ea01ab01f
https://git.kernel.org/stable/c/7ae2c5b89da3cfaf856df880af27d3bb32a74b3d
https://git.kernel.org/stable/c/cd9c88da171a62c4b0f1c70e50c75845969fbc18
https://git.kernel.org/stable/c/dd86064417de828ff2102ddc6049c829bf7585b4
Source Url

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2025-02-26 17:20:34
  • First insertion