SB20250226581 - Improper error handling in Linux kernel arm64 kernel
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper error handling (CVE-ID: CVE-2022-49520)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling within the compat_arm_syscall() function in arch/arm64/kernel/sys_compat.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/095e975f8150ccd7f852eb578c1cdbdd2f517c7a
- https://git.kernel.org/stable/c/3910ae71cb963fa2b68e684489d4fc3d105afda0
- https://git.kernel.org/stable/c/3fed9e551417b84038b15117732ea4505eee386b
- https://git.kernel.org/stable/c/621916afe8cd4f322eb12759b64a2f938d4e551d
- https://git.kernel.org/stable/c/ad97425d23af3c3b8d4f6a2bb666cb485087c007
- https://git.kernel.org/stable/c/efd183d988b416fcdf6f7c298a17ced4859ca77d
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.198