CVE-2022-49790: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Input: iforce - invert valid length check when fetching device IDs syzbot is reporting uninitialized value at iforce_init_device() [1], for commit 6ac0aec6b0a6 ("Input: iforce - allow callers supply data buffer when fetching device IDs") is checking that valid length is shorter than bytes to read. Since iforce_get_id_packet() stores valid length when returning 0, the caller needs to check that valid length is longer than or equals to bytes to read.

Affected products

  • Linux Linux Kernel: from 5.3, before 5.4.225 (fixed in 5.4.225); from 5.5, before 5.10.156 (fixed in 5.10.156); from 5.11, before 5.15.80 (fixed in 5.15.80); from 5.16, before 6.0.10 (fixed in 6.0.10); version 6.1 only

Published 2025-05-01. Last modified 2026-06-17.