CVE-2022-49444

module: fix [e_shstrndx].sh_size=0 OOB access

References

Notes

 carnil> Introduced in ec2a29593c83 ("module: harden ELF info handling"). Vulnerable
 carnil> versions: 5.4.110 5.10.26 5.11.3 5.12-rc1.

Bugs

Status

Branch Status
upstream released (5.19-rc1) [391e982bfa632b8315235d8be9c0a81374c6a19c]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.13-upstream-stable N/A "Fixed before branching point"
6.12-upstream-stable N/A "Fixed before branching point"
6.6-upstream-stable N/A "Fixed before branching point"
6.1-upstream-stable N/A "Fixed before branching point"
5.10-upstream-stable needed
sid released (5.18.5-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security N/A "Fixed before branching point"
5.10-bullseye-security needed