CVE-2022-49407
A memory read error in the Linux kernel’s Distributed Lock Manager could let a program read data it shouldn’t. The bug was fixed by moving a field to the correct structure. Updating to a kernel that includes this patch removes the risk.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, any distribution that uses the kernel before the patch. Typical users are Linux system administrators, servers, and desktop users.
Real-world impact
An attacker could read sensitive data from memory, potentially exposing confidential information or enabling further attacks. The bug could also cause system instability or crashes.
Why this severity
The CVSS score of 9.8 reflects a critical flaw that can be exploited remotely without authentication, giving an attacker full read, write, and execute impact on the system.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the dlm: fix plock invalid read patch.
NVD-referenced vendor advisory
Timeline
- Feb 26, 2025 · Feb 26, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/2c55155cc365861044…patch
- git.kernel.org/stable/c/42252d0d2aa9b94d16…patch
- git.kernel.org/stable/c/49cd9eb7b9a7b88124…patch
- git.kernel.org/stable/c/56aa8d1fbd02357f3b…patch
- git.kernel.org/stable/c/5a1765adf9855cf0f6…patch
- git.kernel.org/stable/c/72f2f68970f9bdc252…patch
- git.kernel.org/stable/c/899bc4429174861122…patch
- git.kernel.org/stable/c/acdad5bc9827922ec2…patch
- git.kernel.org/stable/c/e421872fa17542cf33…patch