CVE-2022-49991

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/06/2025
Last modified:
14/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> mm/hugetlb: avoid corrupting page-&gt;mapping in hugetlb_mcopy_atomic_pte<br /> <br /> In MCOPY_ATOMIC_CONTINUE case with a non-shared VMA, pages in the page<br /> cache are installed in the ptes. But hugepage_add_new_anon_rmap is called<br /> for them mistakenly because they&amp;#39;re not vm_shared. This will corrupt the<br /> page-&gt;mapping used by page cache code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.13 (including) 5.15.65 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 5.19.6 (excluding)
cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.0:rc2:*:*:*:*:*:*