CVE-2022-49564

Summary

In the Linux kernel, the following vulnerability has been resolved:

crypto: qat - add param check for DH

Reject requests with a source buffer that is bigger than the size of the key. This is to prevent a possible integer underflow that might happen when copying the source scatterlist into a linear buffer.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxc9839143ebbf5e821128da44f7e271d745aab19e < e7f979ed51f96495328157df663c835b17db1e30affected
LinuxLinuxc9839143ebbf5e821128da44f7e271d745aab19e < 76c9216833e7c20a67c987cf89719a3f01666aaaaffected
LinuxLinuxc9839143ebbf5e821128da44f7e271d745aab19e < 2acbb8771f6ac82422886e63832ee7a0f4b1635baffected
LinuxLinux4.8affected
LinuxLinux0 < 4.8unaffected
LinuxLinux5.15.58 <= 5.15.*unaffected
LinuxLinux5.18.15 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References