CVE-2022-49030: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: libbpf: Handle size overflow for ringbuf mmap The maximum size of ringbuf is 2GB on x86-64 host, so 2 * max_entries will overflow u32 when mapping producer page and data pages. Only casting max_entries to size_t is not enough, because for 32-bits application on 64-bits kernel the size of read-only mmap region also could overflow size_t. So fixing it by casting the size of read-only mmap region into a __u64 and checking whether or not there will be overflow during mmap.
Affected products
- Linux Linux Kernel: from 5.8, before 5.10.158 (fixed in 5.10.158); from 5.11, before 5.15.82 (fixed in 5.15.82); from 5.16, before 6.0.12 (fixed in 6.0.12); version 6.1 only
Published 2024-10-21. Last modified 2026-08-04.