CVE-2022-49743

Source
https://cve.org/CVERecord?id=CVE-2022-49743
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49743.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49743
Downstream
Published
2025-03-27T16:42:54.289Z
Modified
2026-05-28T03:53:19.701923427Z
Summary
ovl: Use "buf" flexible array for memcpy() destination
Details

In the Linux kernel, the following vulnerability has been resolved:

ovl: Use "buf" flexible array for memcpy() destination

The "buf" flexible array needs to be the memcpy() destination to avoid false positive run-time warning from the recent FORTIFY_SOURCE hardening:

memcpy: detected field-spanning write (size 93) of single field "&fh->fb" at fs/overlayfs/export.c:799 (size 21)

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49743.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cbe7fba8edfc8cb8e621599e376f8ac5c224fa72
Fixed
012cdef22000f3104e4fa8224ad29fde509b8caf
Fixed
a77141a06367825d639ac51b04703d551163e36c
Fixed
07a96977b2f462337a9121302de64277b8747ab1
Fixed
cf8aa9bf97cadf85745506c6a3e244b22c268d63

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49743.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.248
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.93
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.11

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49743.json"