Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2022-49567

5.5 · MEDIUM
Published Feb 26, 2025 linux CWE-908 EPSS 0.28% (20th pctl)

Overview

CVE-2022-49567 is a medium-severity vulnerability affecting linux linux_kernel. It was published on February 26, 2025 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

mm/mempolicy: fix uninit-value in mpol_rebind_policy()

mpol_set_nodemask()(mm/mempolicy.c) does not set up nodemask when

pol->mode is MPOL_LOCAL. Check pol->mode before access

pol->w.cpuset_mems_allowed in mpol_rebind_policy()(mm/mempolicy.c).

BUG: KMSAN: uninit-value in mpol_rebind_policy mm/mempolicy.c:352 [inline]

BUG: KMSAN: uninit-value in mpol_rebind_task+0x2ac/0x2c0 mm/mempolicy.c:368

mpol_rebind_policy mm/mempolicy.c:352 [inline]

mpol_rebind_task+0x2ac/0x2c0 mm/mempolicy.c:368

cpuset_change_task_nodemask kernel/cgroup/cpuset.c:1711 [inline]

cpuset_attach+0x787/0x15e0 kernel/cgroup/cpuset.c:2278

cgroup_migrate_execute+0x1023/0x1d20 kernel/cgroup/cgroup.c:2515

cgroup_migrate kernel/cgroup/cgroup.c:2771 [inline]

cgroup_attach_task+0x540/0x8b0 kernel/cgroup/cgroup.c:2804

__cgroup1_procs_write+0x5cc/0x7a0 kernel/cgroup/cgroup-v1.c:520

cgroup1_tasks_write+0x94/0xb0 kernel/cgroup/cgroup-v1.c:539

cgroup_f

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 0, < 4.9.325 Affected

Frequently Asked Questions

What is CVE-2022-49567?

CVE-2022-49567 is a medium-severity vulnerability affecting linux linux_kernel. It was published on February 26, 2025 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2022-49567?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2022-49567?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2022-49567?

CyberStrike's AI-powered security agents can automatically detect CVE-2022-49567 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.