{"id":"DEBIAN-CVE-2022-49374","details":"In the Linux kernel, the following vulnerability has been resolved:  tipc: check attribute length for bearer name  syzbot reported uninit-value: ===================================================== BUG: KMSAN: uninit-value in string_nocheck lib/vsprintf.c:644 [inline] BUG: KMSAN: uninit-value in string+0x4f9/0x6f0 lib/vsprintf.c:725  string_nocheck lib/vsprintf.c:644 [inline]  string+0x4f9/0x6f0 lib/vsprintf.c:725  vsnprintf+0x2222/0x3650 lib/vsprintf.c:2806  vprintk_store+0x537/0x2150 kernel/printk/printk.c:2158  vprintk_emit+0x28b/0xab0 kernel/printk/printk.c:2256  vprintk_default+0x86/0xa0 kernel/printk/printk.c:2283  vprintk+0x15f/0x180 kernel/printk/printk_safe.c:50  _printk+0x18d/0x1cf kernel/printk/printk.c:2293  tipc_enable_bearer net/tipc/bearer.c:371 [inline]  __tipc_nl_bearer_enable+0x2022/0x22a0 net/tipc/bearer.c:1033  tipc_nl_bearer_enable+0x6c/0xb0 net/tipc/bearer.c:1042  genl_family_rcv_msg_doit net/netlink/genetlink.c:731 [inline]  - Do sanity check the attribute length for TIPC_NLA_BEARER_NAME. - Do not use 'illegal name' in printing message.","modified":"2026-09-01T20:04:54.444157051Z","published":"2025-02-26T07:01:14.060Z","upstream":["CVE-2022-49374"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49374"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49374.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49374.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49374.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}