In the Linux kernel, the following vulnerability has been resolved:
ipv6: Fix signed integer overflow in l2tpip6sendmsg
When len >= INT_MAX - transhdrlen, ulen = len + transhdrlen will be overflow. To fix, we can follow what udpv6 does and subtract the transhdrlen from the max.
[
{
"id": "CVE-2022-49727-10c07af7",
"target": {
"function": "l2tp_ip6_sendmsg",
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"length": 3606.0,
"function_hash": "303277409494840033100803161708782793500"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@034246122f5c5e2e2a0b9fe04e24517920e9beb1",
"signature_type": "Function"
},
{
"id": "CVE-2022-49727-10e31d4e",
"target": {
"function": "l2tp_ip6_sendmsg",
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"length": 3596.0,
"function_hash": "314254626963016949829689610215338014669"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6c4e3486d21173d60925ef52e512cae727b43d30",
"signature_type": "Function"
},
{
"id": "CVE-2022-49727-1b4a7aab",
"target": {
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"line_hashes": [
"84142433928566069005228622122248887239",
"180140298548217584837483754531088761368",
"300586250759316525319123670691364169153",
"112017736316601277747877121058487136664",
"234132458967543337948021779978030738470",
"468271691659318320234862333872538408",
"92988748045821824458053189222633317152"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b8879ca1fd7348b4d5db7db86dcb97f60c73d751",
"signature_type": "Line"
},
{
"id": "CVE-2022-49727-1d87d514",
"target": {
"function": "l2tp_ip6_sendmsg",
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"length": 3606.0,
"function_hash": "303277409494840033100803161708782793500"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@27a37755ceb401111ded76810359d3adc4b268a1",
"signature_type": "Function"
},
{
"id": "CVE-2022-49727-252c21a2",
"target": {
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"line_hashes": [
"84142433928566069005228622122248887239",
"180140298548217584837483754531088761368",
"300586250759316525319123670691364169153",
"112017736316601277747877121058487136664",
"234132458967543337948021779978030738470",
"468271691659318320234862333872538408",
"92988748045821824458053189222633317152"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@034246122f5c5e2e2a0b9fe04e24517920e9beb1",
"signature_type": "Line"
},
{
"id": "CVE-2022-49727-2e67f761",
"target": {
"function": "l2tp_ip6_sendmsg",
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"length": 3619.0,
"function_hash": "221480314215399619873676731073381786785"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f638a84afef3dfe10554c51820c16e39a278c915",
"signature_type": "Function"
},
{
"id": "CVE-2022-49727-39c087ca",
"target": {
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"line_hashes": [
"84142433928566069005228622122248887239",
"180140298548217584837483754531088761368",
"300586250759316525319123670691364169153",
"112017736316601277747877121058487136664",
"234132458967543337948021779978030738470",
"468271691659318320234862333872538408",
"92988748045821824458053189222633317152"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f638a84afef3dfe10554c51820c16e39a278c915",
"signature_type": "Line"
},
{
"id": "CVE-2022-49727-42f306e7",
"target": {
"function": "l2tp_ip6_sendmsg",
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"length": 3606.0,
"function_hash": "303277409494840033100803161708782793500"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f42389d270f2304c8855b0b63498a5a4d0c053d",
"signature_type": "Function"
},
{
"id": "CVE-2022-49727-524d114b",
"target": {
"function": "l2tp_ip6_sendmsg",
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"length": 3587.0,
"function_hash": "163427419955114298433565770969119923849"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2cf73c7cb6125083408d77f43d0e84d86aed0000",
"signature_type": "Function"
},
{
"id": "CVE-2022-49727-58e4b16e",
"target": {
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"line_hashes": [
"84142433928566069005228622122248887239",
"180140298548217584837483754531088761368",
"300586250759316525319123670691364169153",
"112017736316601277747877121058487136664",
"234132458967543337948021779978030738470",
"468271691659318320234862333872538408",
"92988748045821824458053189222633317152"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e818d433fc2718fe4da044ffca7431812a7e04e",
"signature_type": "Line"
},
{
"id": "CVE-2022-49727-72b9e6db",
"target": {
"function": "l2tp_ip6_sendmsg",
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"length": 3676.0,
"function_hash": "324740501881379732713204636393774894153"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e818d433fc2718fe4da044ffca7431812a7e04e",
"signature_type": "Function"
},
{
"id": "CVE-2022-49727-82f0b169",
"target": {
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"line_hashes": [
"84142433928566069005228622122248887239",
"180140298548217584837483754531088761368",
"300586250759316525319123670691364169153",
"112017736316601277747877121058487136664",
"234132458967543337948021779978030738470",
"468271691659318320234862333872538408",
"92988748045821824458053189222633317152"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@27a37755ceb401111ded76810359d3adc4b268a1",
"signature_type": "Line"
},
{
"id": "CVE-2022-49727-9216483f",
"target": {
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"line_hashes": [
"84142433928566069005228622122248887239",
"180140298548217584837483754531088761368",
"300586250759316525319123670691364169153",
"112017736316601277747877121058487136664",
"234132458967543337948021779978030738470",
"468271691659318320234862333872538408",
"92988748045821824458053189222633317152"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6c4e3486d21173d60925ef52e512cae727b43d30",
"signature_type": "Line"
},
{
"id": "CVE-2022-49727-d0ca6617",
"target": {
"function": "l2tp_ip6_sendmsg",
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"length": 3606.0,
"function_hash": "303277409494840033100803161708782793500"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b8879ca1fd7348b4d5db7db86dcb97f60c73d751",
"signature_type": "Function"
},
{
"id": "CVE-2022-49727-d77d638a",
"target": {
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"line_hashes": [
"84142433928566069005228622122248887239",
"180140298548217584837483754531088761368",
"300586250759316525319123670691364169153",
"112017736316601277747877121058487136664",
"234132458967543337948021779978030738470",
"468271691659318320234862333872538408",
"92988748045821824458053189222633317152"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2cf73c7cb6125083408d77f43d0e84d86aed0000",
"signature_type": "Line"
},
{
"id": "CVE-2022-49727-f7e9b50b",
"target": {
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"line_hashes": [
"84142433928566069005228622122248887239",
"180140298548217584837483754531088761368",
"300586250759316525319123670691364169153",
"112017736316601277747877121058487136664",
"234132458967543337948021779978030738470",
"468271691659318320234862333872538408",
"92988748045821824458053189222633317152"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f42389d270f2304c8855b0b63498a5a4d0c053d",
"signature_type": "Line"
}
]