CVE-2022-48630
published 2024-03-05CVE-2022-48630: In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commit…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ
The commit referenced in the Fixes tag removed the 'break' from the else
branch in qcom_rng_read(), causing an infinite loop whenever 'max' is
not a multiple of WORD_SZ. This can be reproduced e.g. by running:
kcapi-rng -b 67 >/dev/null
There are many ways to fix this without adding back the 'break', but
they all seem more awkward than simply adding it back, so do just that.
Tested on a machine with Qualcomm Amberwing processor.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.17.11-1 (bookworm) | linux 5.17.11-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 0f9b7b8df17525e464294c916acc8194ce38446b < 233a3cc60e7a8fe0be8cf9934ae7b67ba25a866c | 233a3cc60e7a8fe0be8cf9934ae7b67ba25a866c |
| linux | linux | >= 184f7bd08ce56f003530fc19f160d54e75bf5c9d < 8be06f62b426801dba43ddf8893952a0e62ab6ae | 8be06f62b426801dba43ddf8893952a0e62ab6ae |
| linux | linux | >= 4.19.236 < 4.19.245 | 4.19.245 |
| linux | linux | >= 5.10.108 < 5.10.118 | 5.10.118 |
| linux | linux | >= 5.15.31 < 5.15.42 | 5.15.42 |
| linux | linux | >= 5.16.17 < 5.17 | 5.17 |
| linux | linux | >= 5.4.187 < 5.4.196 | 5.4.196 |
| linux | linux | >= a680b1832ced3b5fa7c93484248fd221ea0d614b < 05d4d17475d8d094c519bb51658bc47899c175e3 | 05d4d17475d8d094c519bb51658bc47899c175e3 |
| linux | linux | >= a680b1832ced3b5fa7c93484248fd221ea0d614b < 16287397ec5c08aa58db6acf7dbc55470d78087d | 16287397ec5c08aa58db6acf7dbc55470d78087d |
| linux | linux | >= a8e32bbb96c25b7ab29b1894dcd45e0b3b08fd9d < 71a89789552b7faf3ef27969b9bc783fa0df3550 | 71a89789552b7faf3ef27969b9bc783fa0df3550 |
| linux | linux | >= ab9337c7cb6f875b6286440b1adfbeeef2b2b2bd < 8a06f25f5941c145773204f2f7abef95b4ffb8ce | 8a06f25f5941c145773204f2f7abef95b4ffb8ce |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.120-1 | 5.10.120-1 |
| linux | linux_kernel | >= 0 < 5.17.11-1 | 5.17.11-1 |
| linux | linux_kernel | >= 0 < 5.17.11-1 | 5.17.11-1 |
| linux | linux_kernel | >= 0 < 5.17.11-1 | 5.17.11-1 |
| linux | linux_kernel | >= 4.19.236 < 4.19.245 | 4.19.245 |
| linux | linux_kernel | >= 5.10.108 < 5.10.118 | 5.10.118 |
| linux | linux_kernel | >= 5.15.31 < 5.15.42 | 5.15.42 |
| linux | linux_kernel | >= 5.17 < 5.17.10 | 5.17.10 |
| linux | linux_kernel | >= 5.4.187 < 5.4.196 | 5.4.196 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ
vendor_redhat·2024-03-05·CVSS 5.5
CVE-2022-48630 [MEDIUM] CWE-835 kernel: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ
kernel: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ
In the Linux kernel, the following vulnerability has been resolved:
crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ
The commit referenced in the Fixes tag removed the 'break' from the else
branch in qcom_rng_read(), causing an infinite loop whenever 'max' is
not a multiple of WORD_SZ. This can be reproduced e.g. by running:
kcapi-rng -b 67 >/dev/null
There are many ways to fix this without adding back the 'break', but
they all seem more awkward than simply adding it back, so do just that.
Tested on a machine with Qualcomm Amberwing processor.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (R
Debian
CVE-2022-48630: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: qco...
vendor_debian·2022·CVSS 5.5
CVE-2022-48630 [MEDIUM] CVE-2022-48630: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: qco...
In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commit referenced in the Fixes tag removed the 'break' from the else branch in qcom_rng_read(), causing an infinite loop whenever 'max' is not a multiple of WORD_SZ. This can be reproduced e.g. by running: kcapi-rng -b 67 >/dev/null There are many ways to fix this without adding back the 'break', but they all seem more awkward than simply adding it back, so do just that. Tested on a machine with Qualcomm Amberwing processor.
Scope: local
bookworm: resolved (fixed in 5.17.11-1)
bullseye: resolved (fixed in 5.10.120-1)
forky: resolved (fixed in 5.17.11-1)
sid: resolved (fixed in 5.17.11-1)
trixie: resolved (fixed in 5.17.11-1)
OSV
CVE-2022-48630: In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commi
osv·2024-03-05·CVSS 5.5
CVE-2022-48630 [MEDIUM] CVE-2022-48630: In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commi
In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commit referenced in the Fixes tag removed the 'break' from the else branch in qcom_rng_read(), causing an infinite loop whenever 'max' is not a multiple of WORD_SZ. This can be reproduced e.g. by running: kcapi-rng -b 67 >/dev/null There are many ways to fix this without adding back the 'break', but they all seem more awkward than simply adding it back, so do just that. Tested on a machine with Qualcomm Amberwing processor.
GHSA
GHSA-4rpf-4vmp-3hfw: In the Linux kernel, the following vulnerability has been resolved:
crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ
The com
ghsa_unreviewed·2024-03-05
CVE-2022-48630 [MEDIUM] CWE-835 GHSA-4rpf-4vmp-3hfw: In the Linux kernel, the following vulnerability has been resolved:
crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ
The com
In the Linux kernel, the following vulnerability has been resolved:
crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ
The commit referenced in the Fixes tag removed the 'break' from the else
branch in qcom_rng_read(), causing an infinite loop whenever 'max' is
not a multiple of WORD_SZ. This can be reproduced e.g. by running:
kcapi-rng -b 67 >/dev/null
There are many ways to fix this without adding back the 'break', but
they all seem more awkward than simply adding it back, so do just that.
Tested on a machine with Qualcomm Amberwing processor.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/05d4d17475d8d094c519bb51658bc47899c175e3https://git.kernel.org/stable/c/16287397ec5c08aa58db6acf7dbc55470d78087dhttps://git.kernel.org/stable/c/233a3cc60e7a8fe0be8cf9934ae7b67ba25a866chttps://git.kernel.org/stable/c/71a89789552b7faf3ef27969b9bc783fa0df3550https://git.kernel.org/stable/c/8a06f25f5941c145773204f2f7abef95b4ffb8cehttps://git.kernel.org/stable/c/8be06f62b426801dba43ddf8893952a0e62ab6aehttps://git.kernel.org/stable/c/05d4d17475d8d094c519bb51658bc47899c175e3https://git.kernel.org/stable/c/16287397ec5c08aa58db6acf7dbc55470d78087dhttps://git.kernel.org/stable/c/233a3cc60e7a8fe0be8cf9934ae7b67ba25a866chttps://git.kernel.org/stable/c/71a89789552b7faf3ef27969b9bc783fa0df3550https://git.kernel.org/stable/c/8a06f25f5941c145773204f2f7abef95b4ffb8cehttps://git.kernel.org/stable/c/8be06f62b426801dba43ddf8893952a0e62ab6ae
2024-03-05
Published