CVE-2022-48632
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
28/04/2024
Last modified:
03/03/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()<br />
<br />
memcpy() is called in a loop while &#39;operation->length&#39; upper bound<br />
is not checked and &#39;data_idx&#39; also increments.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.10 (including) | 5.10.146 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.71 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 5.19.12 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.0:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.0:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.0:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.0:rc6:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/3b5ab5fbe69ebbee5692c72b05071a43fc0655d8
- https://git.kernel.org/stable/c/48ee0a864d1af02eea98fc825cc230d61517a71e
- https://git.kernel.org/stable/c/dc2a0c587006f29b724069740c48654b9dcaebd2
- https://git.kernel.org/stable/c/de24aceb07d426b6f1c59f33889d6a964770547b
- https://git.kernel.org/stable/c/3b5ab5fbe69ebbee5692c72b05071a43fc0655d8
- https://git.kernel.org/stable/c/48ee0a864d1af02eea98fc825cc230d61517a71e
- https://git.kernel.org/stable/c/dc2a0c587006f29b724069740c48654b9dcaebd2
- https://git.kernel.org/stable/c/de24aceb07d426b6f1c59f33889d6a964770547b



