CVE-2022-49991

MEDIUM

Linux Kernel 5.13-5.15.65, 5.16-5.19.6, 6.0+ - Page Cache Corruption via hugetlb_mcopy_atomic_pte

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: avoid corrupting page->mapping in hugetlb_mcopy_atomic_pte In MCOPY_ATOMIC_CONTINUE case with a non-shared VMA, pages in the page cache are installed in the ptes. But hugepage_add_new_anon_rmap is called for them mistakenly because they're not vm_shared. This will corrupt the page->mapping used by page cache code.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 10.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (12)
linux/Kernel 5.13.0 - 5.15.65linux
linux/Kernel 5.16.0 - 5.19.6linux
Linux/Linux < 5.13
Linux/Linux 5.13
Linux/Linux 5.15.65 - 5.15.*
Linux/Linux 5.19.6 - 5.19.*
Linux/Linux 6.0
Linux/Linux f619147104c8ea71e120e4936d2b68ec11a1e527 - 3ada1b3e58db255a14ec73a59d7913e84dc5a8a4
Linux/Linux f619147104c8ea71e120e4936d2b68ec11a1e527 - ab74ef708dc51df7cf2b8a890b9c6990fac5c0c6
Linux/Linux f619147104c8ea71e120e4936d2b68ec11a1e527 - da60ddd80d09f8371fbba1a238a4b318d13ba698
... and 2 more
Published Jun 18, 2025
Tracked Since Feb 18, 2026