VYPR
High severity7.8NVD Advisory· Published Oct 21, 2024· Updated Aug 4, 2026

CVE-2022-49030

CVE-2022-49030

Description

In the Linux kernel, the following vulnerability has been resolved:

libbpf: Handle size overflow for ringbuf mmap

The maximum size of ringbuf is 2GB on x86-64 host, so 2 * max_entries will overflow u32 when mapping producer page and data pages. Only casting max_entries to size_t is not enough, because for 32-bits application on 64-bits kernel the size of read-only mmap region also could overflow size_t.

So fixing it by casting the size of read-only mmap region into a __u64 and checking whether or not there will be overflow during mmap.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

11
  • osv-coords
    Range: >= 5.8.0, < 5.10.158
  • Linux/Kernelllm-fuzzy10 versions
    (expand)+ 9 more
    • (no CPE)
    • (no CPE)range: 5.8
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.8,<5.10.158
    • cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc5:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc6:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc7:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.