CVE-2022-49401 is a Linux kernel vulnerability in the mm/page_owner component, affecting various Linux kernel versions. The flaw stems from the incorrect use of strlcpy() instead of strscpy() when handling current->comm[], which is not guaranteed to be null-terminated, leading to potential out-of-bounds read access and a kernel crash. This vulnerability has a CVSS v3.1 score of 7.1 (High), indicating a local attack vector with low attack complexity, requiring low privileges and no user interaction. Successful exploitation could lead to high confidentiality impact (information disclosure) and high availability impact (denial of service). There is currently no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.18, < 5.18.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.