CVE-2022-49852

Source
https://cve.org/CVERecord?id=CVE-2022-49852
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49852.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49852
Downstream
Published
2025-05-01T14:10:07.001Z
Modified
2026-05-28T03:53:54.820760586Z
Summary
riscv: process: fix kernel info leakage
Details

In the Linux kernel, the following vulnerability has been resolved:

riscv: process: fix kernel info leakage

threadstruct's s[12] may contain random kernel memory content, which may be finally leaked to userspace. This is a security hole. Fix it by clearing the s[12] array in threadstruct when fork.

As for kthread case, it's better to clear the s[12] array as well.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49852.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7db91e57a0acde126a162ababfb1e0ab190130cb
Fixed
c4601d30f7d989b4f354df899ab85b5f7a750d30
Fixed
c5c0b3167537793a7cf936fb240366eefd2fc7fb
Fixed
e56d18a976dda653194218df6d40d8122c775712
Fixed
cc36c7fa5d9384602529ba3eea8c5daee7be4dbc
Fixed
358a68f98304b40b201ba5afe94c20355aa3dc68
Fixed
6510c78490c490a6636e48b61eeaa6fb65981f4b

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49852.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.267
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.225
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.155
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.79
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.0.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49852.json"