CVE-2022-49743

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/03/2025
Last modified:
19/01/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ovl: Use "buf" flexible array for memcpy() destination<br /> <br /> The "buf" flexible array needs to be the memcpy() destination to avoid<br /> false positive run-time warning from the recent FORTIFY_SOURCE<br /> hardening:<br /> <br /> memcpy: detected field-spanning write (size 93) of single field "&amp;fh-&gt;fb"<br /> at fs/overlayfs/export.c:799 (size 21)

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.15.93 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.11 (excluding)