cbcvebase.
CVE-2022-48627
published 2024-03-02

CVE-2022-48627: In the Linux kernel, the following vulnerability has been resolved: vt: fix memory overlapping when deleting chars in the buffer A memory overlapping copy…

PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.28%
20.0th percentile
In the Linux kernel, the following vulnerability has been resolved: vt: fix memory overlapping when deleting chars in the buffer A memory overlapping copy occurs when deleting a long line. This memory overlapping copy can cause data corruption when scr_memcpyw is optimized to memcpy because memcpy does not ensure its behavior if the destination buffer overlaps with the source buffer. The line buffer is not always broken, because the memcpy utilizes the hardware acceleration, whose result is not deterministic. Fix this problem by using replacing the scr_memcpyw with scr_memmovew.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < c8686c014b5e872ba7e334f33ca553f14446fc29c8686c014b5e872ba7e334f33ca553f14446fc29
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < 815be99d934e3292906536275f2b8d5131cdf52c815be99d934e3292906536275f2b8d5131cdf52c
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < bfee93c9a6c395f9aa62268f1cedf64999844926bfee93c9a6c395f9aa62268f1cedf64999844926
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < 57964a5710252bc82fe22d9fa98c180c58c2024457964a5710252bc82fe22d9fa98c180c58c20244
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < 14d2cc21ca622310babf373e3a8f0b40acfe826514d2cc21ca622310babf373e3a8f0b40acfe8265
linuxlinux>= 81732c3b2fede049a692e58a7ceabb6d18ffb18c < 39cdb68c64d84e71a4a717000b6e5de208ee60cc39cdb68c64d84e71a4a717000b6e5de208ee60cc
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel3.7 – 4.19.312
linuxlinux_kernel>= 4.20 < 5.4.2745.4.274
linuxlinux_kernel>= 5.11 < 5.15.565.15.56
linuxlinux_kernel>= 5.16 < 5.18.135.18.13
linuxlinux_kernel>= 5.5 < 5.10.1325.10.132

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.