CVE-2022-2010
published 2022-07-28CVE-2022-2010: Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially…
PriorityP345critical9.3CVSS 3.1
AVNACLPRNUIRSCCHINAH
EPSS
1.08%
61.4th percentile
Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 102.0.5005.115-1~deb11u1 | 102.0.5005.115-1~deb11u1 |
| chromium | chromium | >= 0 < 102.0.5005.115-1 | 102.0.5005.115-1 |
| chromium | chromium | >= 0 < 102.0.5005.115-1 | 102.0.5005.115-1 |
| chromium | chromium | >= 0 < 102.0.5005.115-1 | 102.0.5005.115-1 |
| debian | chromium | < chromium 102.0.5005.115-1 (bookworm) | chromium 102.0.5005.115-1 (bookworm) |
| fedoraproject | fedora | — | — |
| chrome | < 102.0.5005.115 | 102.0.5005.115 | |
| chrome | >= unspecified < 102.0.5005.115 | 102.0.5005.115 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.19.3CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H
osv9.3CRITICAL
cisa10.0CRITICAL
vendor_debian9.3CRITICAL
vendor_msrc9.3CRITICAL
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3h6m-v52v-hvmw: Out of bounds read in compositing in Google Chrome prior to 102
ghsa_unreviewed·2022-07-29
CVE-2022-2010 [CRITICAL] CWE-125 GHSA-3h6m-v52v-hvmw: Out of bounds read in compositing in Google Chrome prior to 102
Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
OSV
CVE-2022-2010: Out of bounds read in compositing in Google Chrome prior to 102
osv·2022-07-28·CVSS 9.3
CVE-2022-2010 [CRITICAL] CVE-2022-2010: Out of bounds read in compositing in Google Chrome prior to 102
Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
CISA
Microsoft Windows Remote Code Execution Vulnerability
cisa·2022-09-15·CVSS 7.8
CVE-2010-2568 [HIGH] CWE-20 Microsoft Windows Remote Code Execution Vulnerability
Vulnerability: Microsoft Windows Remote Code Execution Vulnerability
Affected: Microsoft Windows
Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user.
Required Action: Apply updates per vendor instructions.
Notes: https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-046; https://nvd.nist.gov/vuln/detail/CVE-2010-2568
Remediation Due Date: 2022-10-06
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2022-2010
vendor_chrome·2022-07-27·CVSS 9.3
CVE-2022-2010 [CRITICAL] Long Term Support Channel Update for ChromeOS: CVE-2022-2010
Long Term Support Channel Update for ChromeOS
CVE-2022-2010
Microsoft
Chromium: CVE-2022-2010 Out of bounds read in compositing
vendor_msrc·2022-06-14·CVSS 9.3
CVE-2022-2010 [CRITICAL] Chromium: CVE-2022-2010 Out of bounds read in compositing
Chromium: CVE-2022-2010 Out of bounds read in compositing
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.41
6/13/2022
102.0.5005.115
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browse
Chrome
Stable Channel Update for Desktop: CVE-2022-2007
vendor_chrome·2022-06-09·CVSS 8.8
CVE-2022-2007 [HIGH] Stable Channel Update for Desktop: CVE-2022-2007
Stable Channel Update for Desktop
CVE-2022-2007: Use after free in WebGPU. Reported by David Manouchehri on 2022-05-17 [$TBD][ 1317673 ] High CVE-2022-2008: Out of bounds memory access in WebGL
Reported by khangkito - Tran Van Khang (VinCSS) on 2022-04-19 [$NA][ 1325298 ] High CVE-2022-2010: Out of bounds read in compositing
Severity: high
CISA
Microsoft PowerPoint Buffer Overflow Vulnerability
cisa·2022-06-08·CVSS 7.8
CVE-2010-2572 [HIGH] CWE-119 Microsoft PowerPoint Buffer Overflow Vulnerability
Vulnerability: Microsoft PowerPoint Buffer Overflow Vulnerability
Affected: Microsoft PowerPoint
Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-2572
Remediation Due Date: 2022-06-22
CISA
Adobe Flash Player Memory Corruption Vulnerability
cisa·2022-06-08·CVSS 7.8
CVE-2010-1297 [HIGH] CWE-787 Adobe Flash Player Memory Corruption Vulnerability
Vulnerability: Adobe Flash Player Memory Corruption Vulnerability
Affected: Adobe Flash Player
Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-1297
Remediation Due Date: 2022-06-22
CISA
Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability
cisa·2022-06-08·CVSS 7.3
CVE-2010-2883 [HIGH] CWE-119 Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability
Vulnerability: Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability
Affected: Adobe Acrobat and Reader
Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-2883
Remediation Due Date: 2022-06-22
CISA
Red Hat JBoss Authentication Bypass Vulnerability
cisa·2022-05-25·CVSS 5.3
CVE-2010-0738 [MEDIUM] CWE-264 Red Hat JBoss Authentication Bypass Vulnerability
Vulnerability: Red Hat JBoss Authentication Bypass Vulnerability
Affected: Red Hat JBoss
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-0738
Remediation Due Date: 2022-06-15
CISA
Red Hat JBoss Information Disclosure Vulnerability
cisa·2022-05-25·CVSS 7.5
CVE-2010-1428 [HIGH] CWE-264 Red Hat JBoss Information Disclosure Vulnerability
Vulnerability: Red Hat JBoss Information Disclosure Vulnerability
Affected: Red Hat JBoss
Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-1428
Remediation Due Date: 2022-06-15
CISA
Oracle JRE Unspecified Vulnerability
cisa·2022-05-25·CVSS 9.8
CVE-2010-0840 [CRITICAL] Oracle JRE Unspecified Vulnerability
Vulnerability: Oracle JRE Unspecified Vulnerability
Affected: Oracle Java Runtime Environment (JRE)
Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-0840
Remediation Due Date: 2022-06-15
CISA
Ubiquiti AirOS Command Injection Vulnerability
cisa·2022-04-15·CVSS 9.8
CVE-2010-5330 [CRITICAL] CWE-77 Ubiquiti AirOS Command Injection Vulnerability
Vulnerability: Ubiquiti AirOS Command Injection Vulnerability
Affected: Ubiquiti AirOS
Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-5330
Remediation Due Date: 2022-05-06
CISA
Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability
cisa·2022-03-28·CVSS 7.8
CVE-2010-4398 [HIGH] CWE-119 Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability
Vulnerability: Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability
Affected: Microsoft Windows
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-4398
Remediation Due Date: 2022-04-21
CISA
Exim Heap-Based Buffer Overflow Vulnerability
cisa·2022-03-25·CVSS 9.8
CVE-2010-4344 [CRITICAL] CWE-119 Exim Heap-Based Buffer Overflow Vulnerability
Vulnerability: Exim Heap-Based Buffer Overflow Vulnerability
Affected: Exim Exim
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-4344
Remediation Due Date: 2022-04-15
CISA
Adobe ColdFusion Directory Traversal Vulnerability
cisa·2022-03-25·CVSS 9.8
CVE-2010-2861 [CRITICAL] CWE-22 Adobe ColdFusion Directory Traversal Vulnerability
Vulnerability: Adobe ColdFusion Directory Traversal Vulnerability
Affected: Adobe ColdFusion
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-2861
Remediation Due Date: 2022-04-15
CISA
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
cisa·2022-03-25·CVSS 7.5
CVE-2010-3035 [HIGH] CWE-20 Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Vulnerability: Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Affected: Cisco IOS XR
Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-3035
Remediation Due Date: 2022-04-15
CISA
Exim Privilege Escalation Vulnerability
cisa·2022-03-25·CVSS 7.8
CVE-2010-4345 [HIGH] CWE-264 Exim Privilege Escalation Vulnerability
Vulnerability: Exim Privilege Escalation Vulnerability
Affected: Exim Exim
Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-4345
Remediation Due Date: 2022-04-15
CISA
Microsoft Office Stack-based Buffer Overflow Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2010-3333 [HIGH] CWE-119 Microsoft Office Stack-based Buffer Overflow Vulnerability
Vulnerability: Microsoft Office Stack-based Buffer Overflow Vulnerability
Affected: Microsoft Office
A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-3333
Remediation Due Date: 2022-03-24
CISA
Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2010-0188 [HIGH] CWE-94 Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability
Vulnerability: Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability
Affected: Adobe Reader and Acrobat
Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-0188
Remediation Due Date: 2022-03-24
CISA
Microsoft Windows Kernel Exception Handler Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2010-0232 [HIGH] CWE-264 Microsoft Windows Kernel Exception Handler Vulnerability
Vulnerability: Microsoft Windows Kernel Exception Handler Vulnerability
Affected: Microsoft Windows
The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-0232
Remediation Due Date: 2022-03-24
Debian
CVE-2022-2010: chromium - Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allow...
vendor_debian·2022·CVSS 9.3
CVE-2022-2010 [CRITICAL] CVE-2022-2010: chromium - Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allow...
Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 102.0.5005.115-1)
bullseye: resolved (fixed in 102.0.5005.115-1~deb11u1)
forky: resolved (fixed in 102.0.5005.115-1)
sid: resolved (fixed in 102.0.5005.115-1)
trixie: resolved (fixed in 102.0.5005.115-1)
CISA
Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability
cisa·2021-12-10·CVSS 8.8
CVE-2010-1871 [HIGH] CWE-20 Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability
Vulnerability: Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability
Affected: Red Hat JBoss Seam 2
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-1871
Remediation Due Date: 2022-06-10
CISA
SAP NetWeaver Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 10.0
CVE-2010-5326 [CRITICAL] SAP NetWeaver Remote Code Execution Vulnerability
Vulnerability: SAP NetWeaver Remote Code Execution Vulnerability
Affected: SAP NetWeaver
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-5326
Remediation Due Date: 2022-05-03
Suricata
GPL NETBIOS DCERPC CoGetInstanceFromFile little endian overflow attempt
suricata·2010-09-23
CVE-2003-0995 GPL NETBIOS DCERPC CoGetInstanceFromFile little endian overflow attempt
GPL NETBIOS DCERPC CoGetInstanceFromFile little endian overflow attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 135 (msg:"GPL NETBIOS DCERPC CoGetInstanceFromFile little endian overflow attempt"; flow:established,to_server; flowbits:isset,smb.tree.bind.msqueue; content:"|05|"; depth:1; byte_test:1,&,16,3,relative; content:"|00|"; offset:1; depth:1; content:"|01 00|"; distance:19; within:2; byte_test:4,>,128,20,relative,little; reference:cve,2003-0995; reference:url,www.eeye.com/html/Research/Advisories/AD20030910.html; reference:url,www.microsoft.com/technet/security/bulletin/MS03-026.mspx; classtype:attempted-admin; sid:2103158; rev:8; metadata:created_at 2010_09_23, cve CVE_2003_0995, confidence Medium, signature_severity Informational, updated_at 2022_04_18;)
Suricata
ET WEB_SPECIFIC_APPS Francisco Burzi PHP-Nuke SQL Injection Attempt -- index.php clickurl ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-0372 [HIGH] ET WEB_SPECIFIC_APPS Francisco Burzi PHP-Nuke SQL Injection Attempt -- index.php clickurl ASCII
ET WEB_SPECIFIC_APPS Francisco Burzi PHP-Nuke SQL Injection Attempt -- index.php clickurl ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Francisco Burzi PHP-Nuke SQL Injection Attempt -- index.php clickurl ASCII"; flow:established,to_server; http.uri; content:"/modules/Advertising/admin/index.php?"; nocase; content:"clickurl="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0372; reference:url,www.securityfocus.com/bid/22116; classtype:web-application-attack; sid:2005478; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2022_04_18, mitre_tactic_id
No public exploits indexed.
Qualys
June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical.
blogs_qualys·2022-06-14·CVSS 7.8
[HIGH] June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
The June 2022 Microsoft Vulnerabilities Are Classified As Follows:
Notable Microsoft Vulnerabilities Patched
Microsoft Guidance on Intel Processor MMIO Stale Data Vulnerabilities
Windows Server 2022 Azure Edition Core Hotpatch (KB5014677) OS Build 20348.770
Microsoft Critical and Important Vulnerability Highlights
Microsoft Last But Not Least
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Qualys Monthly Webinar Series
Join the webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 55 vulnerabilities (aka flaws) in the June
Qualys
June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical. | Qualys
blogs_qualys·2022-06-14·CVSS 7.8
[HIGH] June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The June 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Notable Microsoft Vulnerabilities Patched
- Microsoft Guidance on Intel Processor MMIO Stale Data Vulnerabilities
- Windows Server 2022 Azure Edition Core Hotpatch (KB5014677) OS Build 20348.770
- Microsoft Critical and Important Vulnerability Highlights
- Microsoft Last But Not Least
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Qualys Monthly Webinar Series
- Join the webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 55 vulnerabilities (aka fl
Bugzilla
CVE-2022-50315 kernel: ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS
bugzilla·2025-09-15·CVSS 7.8
CVE-2022-50315 [HIGH] CVE-2022-50315 kernel: ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS
CVE-2022-50315 kernel: ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS
In the Linux kernel, the following vulnerability has been resolved:
ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS
UBSAN complains about array-index-out-of-bounds:
[ 1.980703] kernel: UBSAN: array-index-out-of-bounds in /build/linux-9H675w/linux-5.15.0/drivers/ata/libahci.c:968:41
[ 1.980709] kernel: index 15 is out of range for type 'ahci_em_priv [8]'
[ 1.980713] kernel: CPU: 0 PID: 209 Comm: scsi_eh_8 Not tainted 5.15.0-25-generic #25-Ubuntu
[ 1.980716] kernel: Hardware name: System manufacturer System Product Name/P5Q3, BIOS 1102 06/11/2010
[ 1.980718] kernel: Call Trace:
[ 1.980721] kernel:
[ 1.980723] kernel: show_stack+0x52/0x58
[ 1.980729] kernel: dump_stack_lvl+0x4a/0x5f
[ 1.980734] kernel: dump_
https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop.htmlhttps://crbug.com/1325298https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/https://security.gentoo.org/glsa/202208-25https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop.htmlhttps://crbug.com/1325298https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/https://security.gentoo.org/glsa/202208-25
2022-07-28
Published