CVE-2022-49078 Details
Description
In the Linux kernel, the following vulnerability has been resolved: lz4: fix LZ4_decompress_safe_partial read out of bound When partialDecoding, it is EOF if we've either filled the output buffer or can't proceed with reading an offset for following match. In some extreme corner cases when compressed data is suitably corrupted, UAF will occur. As reported by KASAN [1], LZ4_decompress_safe_partial may lead to read out of bound problem during decoding. lz4 upstream has fixed it [2] and this issue has been disscussed here [3] before. current decompression routine was ported from lz4 v1.8.3, bumping lib/lz4 to v1.9.+ is certainly a huge work to be done later, so, we'd better fix it first. [1] https://lore.kernel.org/all/[email protected]/ [2] https://github.com/lz4/lz4/commit/c5d6f8a8be3927c0bec91bcc58667a6cfad244ad# [3] https://lore.kernel.org/all/[email protected]/
A use-after-free vulnerability has been identified in the Linux kernel's handling of LZ4 decompression. This issue arises in the LZ4_decompress_safe_partial function, where partial decoding can lead to an out-of-bounds read. The vulnerability occurs when the decompression routine encounters corrupted compressed data, creating extreme corner cases that the current decoding logic cannot properly handle. This problem was introduced when the decompression routine was ported from LZ4 version 1.8.3, and while the LZ4 upstream has addressed the issue, integrating the latest version into the Linux kernel will require significant effort.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/467d5e200ab4486b744fe1776154a43d1aa22d4b | kernel.org | Patch |
| https://git.kernel.org/stable/c/6adc01a7aa37445dafe8846faa0610a86029b253 | kernel.org | Patch |
| https://git.kernel.org/stable/c/73953dfa9d50e5c9fe98ee13fd1d3427aa12a0a3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9fb8bc6cfc58773ce95414e11c9ccc8fc6ac4927 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e64dbe97c05c769525cbca099ddbd22485630235 | kernel.org | Patch |
| https://git.kernel.org/stable/c/eafc0a02391b7b36617b36c97c4b5d6832cf5e24 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.20, < 5.4.189 >= 5.5, < 5.10.111 >= 5.11, < 5.15.34 >= 5.16, < 5.16.20 >= 5.17, < 5.17.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 19, 2025 | Modified Analysis | [email protected] |
| Mar 25, 2025 | Initial Analysis | [email protected] |
| Feb 27, 2025 | CVE Modified | CISA-ADP |
| Feb 26, 2025 | New CVE Received | kernel.org |