SB20250226625 - Integer underflow in Linux kernel include asm
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer underflow (CVE-ID: CVE-2022-49611)
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to integer underflow within the SYM_INNER_LABEL() function in arch/x86/kvm/vmx/vmenter.S, within the spectre_v2_select_mitigation() function in arch/x86/kernel/cpu/bugs.c. A local user can execute arbitrary code.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/17a9fc4a7b91f8599223631bb6ae6416bc0de1c0
- https://git.kernel.org/stable/c/3d323b99ff5c8c57005184056d65f6af5b0479d8
- https://git.kernel.org/stable/c/4d7f72b6e1bc630bec7e4cd51814bc2b092bf153
- https://git.kernel.org/stable/c/8c38306e2e9257af4af2819aa287a4711ff36329
- https://git.kernel.org/stable/c/8d5cff499a6d740c91ff37963907e0e983c37f0f
- https://git.kernel.org/stable/c/9756bba28470722dacb79ffce554336dd1f6a6cd
- https://git.kernel.org/stable/c/f744b88dfc201bf8092833ec70b23c720188b527
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.266