PT-2025-8098 · Linux+1 · Linux Kernel+1

·

CVE-2022-49170

·

Published

2022-03-03

·

Updated

2026-08-13

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 5.17-rc4 through 5.17-rc6 linux-image-5.10.142-1-generic linux-image-5.10.142-1-hardened linux-image-5.15.0-33-generic linux-image-5.15.0-33-hardened linux-image-5.15.0-33-lowlatency linux-image-5.15.0-70-generic linux-image-5.15.0-70-hardened linux-image-5.15.0-70-lowlatency
Description An array-index-out-of-bounds issue exists in the Linux kernel when mounting and operating a corrupted image. The root cause is a missing sanity check on the curseg->alloc type variable within the sanity check curseg() function, which leads to out-of-bounds access of the sbi->block count[] array. This can impact the confidentiality, integrity, and availability of protected information.
Recommendations Update the Linux kernel to a version where the sanity check for curseg->alloc type has been implemented. Update linux-image-5.10.142-1-generic to a patched version. Update linux-image-5.10.142-1-hardened to a patched version. Update linux-image-5.15.0-33-generic to a patched version. Update linux-image-5.15.0-33-hardened to a patched version. Update linux-image-5.15.0-33-lowlatency to a patched version. Update linux-image-5.15.0-70-generic to a patched version. Update linux-image-5.15.0-70-hardened to a patched version. Update linux-image-5.15.0-70-lowlatency to a patched version.

Exploit

Fix

Buffer Overflow

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01493
CVE-2022-49170

Affected Products

Astra Linux
Linux Kernel