CVE-2022-49180 Details
Description
In the Linux kernel, the following vulnerability has been resolved: LSM: general protection fault in legacy_parse_param The usual LSM hook "bail on fail" scheme doesn't work for cases where a security module may return an error code indicating that it does not recognize an input. In this particular case Smack sees a mount option that it recognizes, and returns 0. A call to a BPF hook follows, which returns -ENOPARAM, which confuses the caller because Smack has processed its data. The SELinux hook incorrectly returns 1 on success. There was a time when this was correct, however the current expectation is that it return 0 on success. This is repaired.
A vulnerability in the Linux kernel's handling of legacy mount options can lead to a general protection fault. This issue arises within the Linux Security Module (LSM) framework, where the 'bail on fail' scheme fails to address scenarios where a security module returns an error code indicating unrecognized input. In this case, the Smack security module correctly acknowledges a mount option and returns 0, but subsequent BPF hook calls return -ENOPARAM, creating confusion. Additionally, the SELinux hook improperly indicates success by returning 1 instead of the expected 0, contributing to the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/00fc07fa0b4a004711b6e1a944f0d2e46f7093b7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/2784604c8c6fc523248f8f80a421c313a9d790b7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/cadae7c5e477aaafcba819b8e4a3d1c1a1503b62 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ddcdda888e14ca451b3ee83d11b65b2a9c8e783b | kernel.org | Patch |
| https://git.kernel.org/stable/c/ecff30575b5ad0eda149aadad247b7f75411fd47 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f3f93a1aaafc3032e0a9655fb43deccfb3e953a3 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | < 5.4.189 >= 5.5, < 5.10.110 >= 5.11, < 5.15.33 >= 5.16, < 5.16.19 >= 5.17, < 5.17.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Oct 22, 2025 | Initial Analysis | [email protected] |
| Feb 26, 2025 | New CVE Received | kernel.org |