CVE-2022-49478
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
media: pvrusb2: fix array-index-out-of-bounds in pvr2_i2c_core_init
Syzbot reported that -1 is used as array index. The problem was in missing validation check.
hdw->unit_number is initialized with -1 and then if init table walk fails this value remains unchanged. Since code blindly uses this member for array indexing adding sanity check is the easiest fix for that.
hdw->workpoll initialization moved upper to prevent warning in __flush_work.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | d855497edbfbf9e19a17f4a1154bca69cb4bd9ba < 4351bfe36aba9fa7dc9d68d498d25d41a0f45e67 | affected |
| Linux | Linux | d855497edbfbf9e19a17f4a1154bca69cb4bd9ba < 2e004fe914b243db41fa96f9e583385f360ea58e | affected |
| Linux | Linux | d855497edbfbf9e19a17f4a1154bca69cb4bd9ba < a3660e06675bccec4bf149c7229ea1d491ba10d7 | affected |
| Linux | Linux | d855497edbfbf9e19a17f4a1154bca69cb4bd9ba < 1310fc3538dcc375a2f46ef0a438512c2ca32827 | affected |
| Linux | Linux | d855497edbfbf9e19a17f4a1154bca69cb4bd9ba < a3304766d9384886e6d3092c776273526947a2e9 | affected |
| Linux | Linux | d855497edbfbf9e19a17f4a1154bca69cb4bd9ba < 3309c2c574e13b21b44729f5bdbf21f60189b79a | affected |
| Linux | Linux | d855497edbfbf9e19a17f4a1154bca69cb4bd9ba < f99a8b1ec0eddc2931aeaa4f490277a15b39f511 | affected |
| Linux | Linux | d855497edbfbf9e19a17f4a1154bca69cb4bd9ba < 24e807541e4a9263ed928e6ae3498de3ad43bd1e | affected |
| Linux | Linux | d855497edbfbf9e19a17f4a1154bca69cb4bd9ba < 471bec68457aaf981add77b4f590d65dd7da1059 | affected |
| Linux | Linux | 2.6.18 | affected |
| Linux | Linux | 0 < 2.6.18 | unaffected |
| Linux | Linux | 4.9.318 <= 4.9.* | unaffected |
| Linux | Linux | 4.14.283 <= 4.14.* | unaffected |
| Linux | Linux | 4.19.247 <= 4.19.* | unaffected |
| Linux | Linux | 5.4.198 <= 5.4.* | unaffected |
| Linux | Linux | 5.10.121 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.46 <= 5.15.* | unaffected |
| Linux | Linux | 5.17.14 <= 5.17.* | unaffected |
| Linux | Linux | 5.18.3 <= 5.18.* | unaffected |
| Linux | Linux | 5.19 <= * | unaffected |
Weaknesses
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://git.kernel.org/stable/c/4351bfe36aba9fa7dc9d68d498d25d41a0f45e67
- https://git.kernel.org/stable/c/2e004fe914b243db41fa96f9e583385f360ea58e
- https://git.kernel.org/stable/c/a3660e06675bccec4bf149c7229ea1d491ba10d7
- https://git.kernel.org/stable/c/1310fc3538dcc375a2f46ef0a438512c2ca32827
- https://git.kernel.org/stable/c/a3304766d9384886e6d3092c776273526947a2e9
- https://git.kernel.org/stable/c/3309c2c574e13b21b44729f5bdbf21f60189b79a
- https://git.kernel.org/stable/c/f99a8b1ec0eddc2931aeaa4f490277a15b39f511
- https://git.kernel.org/stable/c/24e807541e4a9263ed928e6ae3498de3ad43bd1e
- https://git.kernel.org/stable/c/471bec68457aaf981add77b4f590d65dd7da1059
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.