CVE-2022-49643

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-49643
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49643.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49643
Downstream
Related
Published
2025-02-26T02:23:49.658Z
Modified
2025-11-27T02:33:42.343701Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
ima: Fix a potential integer overflow in ima_appraise_measurement
Details

In the Linux kernel, the following vulnerability has been resolved:

ima: Fix a potential integer overflow in imaappraisemeasurement

When the ima-modsig is enabled, the rc passed to evm_verifyxattr() may be negative, which may cause the integer overflow problem.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/blob/cc431b3424123d84bcd7afd4de150b33f117a8ef/cves/2022/49xxx/CVE-2022-49643.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
39b07096364a42c516415d5f841069e885234e61
Fixed
388f3df7c3c8b7f2a32b9ae0a9b2f9f6ad3b1b77
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
39b07096364a42c516415d5f841069e885234e61
Fixed
831e190175f10652be93b08436cc7bf2e62e4bb6
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
39b07096364a42c516415d5f841069e885234e61
Fixed
c8d5d81940938b5f6c0f495ca9538e7740416f30
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
39b07096364a42c516415d5f841069e885234e61
Fixed
640cea4c2839a821adfbb703b590a5928abe9286
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
39b07096364a42c516415d5f841069e885234e61
Fixed
d2ee2cfc4aa85ff6a2a3b198a3a524ec54e3d999

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.4.0
Fixed
5.4.207
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.132
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.56
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.18.13