CVE-2022-49122

Updated: 2025-10-22 00:32:45.454105

Description:

In the Linux kernel, the following vulnerability has been resolved: dm ioctl: prevent potential spectre v1 gadget It appears like cmd could be a Spectre v1 gadget as it's supplied by a user and used as an array index. Prevent the contents of kernel memory from being leaked to userspace via speculative execution by using array_index_nospec.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-10-24 08:53:33 Ignored due to low severity
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Released CLSA-2025:1757967705 2025-09-30 05:42:06
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Released CLSA-2025:1749568993 2025-06-11 00:58:46
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Released CLSA-2025:1749562017 2025-06-11 00:58:47
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Already Fixed 2025-06-25 02:58:09
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-10-24 08:53:32 Ignored due to low severity
Oracle Linux 7 ELS kernel 3.10.0 5.5 MEDIUM Released CLSA-2025:1757698145 2025-09-12 19:20:59
RHEL 7 ELS kernel 3.10.0 5.5 MEDIUM Released CLSA-2025:1757693980 2025-09-13 06:30:23
Ubuntu 16.04 ELS linux-hwe 4.15.0 5.5 MEDIUM Ignored 2025-10-24 08:54:18 Ignored due to low severity
Ubuntu 16.04 ELS linux 4.4.0 5.5 MEDIUM Ignored 2025-10-24 08:54:10 Ignored due to low severity