CVE-2022-48732

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/06/2024
Last modified:
19/08/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/nouveau: fix off by one in BIOS boundary checking<br /> <br /> Bounds checking when parsing init scripts embedded in the BIOS reject<br /> access to the last byte. This causes driver initialization to fail on<br /> Apple eMac&amp;#39;s with GeForce 2 MX GPUs, leaving the system with no working<br /> console.<br /> <br /> This is probably only seen on OpenFirmware machines like PowerPC Macs<br /> because the BIOS image provided by OF is only the used parts of the ROM,<br /> not a power-of-two blocks read from PCI directly so PCs always have<br /> empty bytes at the end that are never accessed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.8 (including) 4.9.300 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.10 (including) 4.14.265 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.15 (including) 4.19.228 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.20 (including) 5.4.178 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.99 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.22 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 5.16.8 (excluding)