CVE-2022-49870 Details
Description
In the Linux kernel, the following vulnerability has been resolved: capabilities: fix undefined behavior in bit shift for CAP_TO_MASK Shifting signed 32-bit value by 31 bits is undefined, so changing significant bit to unsigned. The UBSAN warning calltrace like below: UBSAN: shift-out-of-bounds in security/commoncap.c:1252:2 left shift of 1 by 31 places cannot be represented in type 'int' Call Trace: <TASK> dump_stack_lvl+0x7d/0xa5 dump_stack+0x15/0x1b ubsan_epilogue+0xe/0x4e __ubsan_handle_shift_out_of_bounds+0x1e7/0x20c cap_task_prctl+0x561/0x6f0 security_task_prctl+0x5a/0xb0 __x64_sys_prctl+0x61/0x8f0 do_syscall_64+0x58/0x80 entry_SYSCALL_64_after_hwframe+0x63/0xcd </TASK>
A vulnerability in the Linux kernel's handling of capabilities has been addressed. The issue arose from shifting a signed 32-bit value by 31 bits, which is undefined behavior. This vulnerability was related to the CAP_TO_MASK functionality, where the significant bit needed to be changed to unsigned to avoid the undefined behavior. The issue triggered a Undefined Behavior Sanitizer (UBSAN) warning, indicating a shift-out-of-bounds error.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/151dc8087b5609e53b069c068e3f3ee100efa586 | kernel.org | Patch |
| https://git.kernel.org/stable/c/27bdb134c043ff32c459d98f16550d0ffa0b3c34 | kernel.org | Patch |
| https://git.kernel.org/stable/c/46653972e3ea64f79e7f8ae3aa41a4d3fdb70a13 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5661f111a1616ac105ec8cec81bff99b60f847ac | kernel.org | Patch |
| https://git.kernel.org/stable/c/5b79fa628e2ab789e629a83cd211ef9b4c1a593e | kernel.org | Patch |
| https://git.kernel.org/stable/c/65b0bc7a0690861812ade523d19f82688ab819dc | kernel.org | Patch |
| https://git.kernel.org/stable/c/dbaab08c8677d598244d21afb7818e44e1c5d826 | kernel.org | Patch |
| https://git.kernel.org/stable/c/fcbd2b336834bd24e1d9454ad5737856470c10d7 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.25, < 4.9.334 >= 4.10, < 4.14.300 >= 4.15, < 4.19.267 >= 4.20, < 5.4.225 >= 5.5, < 5.10.155 >= 5.11, < 5.15.79 >= 5.16, < 6.0.9 6.1 rc1 6.1 rc2 6.1 rc3 6.1 rc4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Nov 10, 2025 | Initial Analysis | [email protected] |
| May 1, 2025 | New CVE Received | kernel.org |