CVE-2022-48632
published 2024-04-28CVE-2022-48632: In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() memcpy() is…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()
memcpy() is called in a loop while 'operation->length' upper bound
is not checked and 'data_idx' also increments.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.2-1 (bookworm) | linux 6.0.2-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= b5b5b32081cd206baa6e58cca7f112d9723785d6 < 48ee0a864d1af02eea98fc825cc230d61517a71e | 48ee0a864d1af02eea98fc825cc230d61517a71e |
| linux | linux | >= b5b5b32081cd206baa6e58cca7f112d9723785d6 < dc2a0c587006f29b724069740c48654b9dcaebd2 | dc2a0c587006f29b724069740c48654b9dcaebd2 |
| linux | linux | >= b5b5b32081cd206baa6e58cca7f112d9723785d6 < 3b5ab5fbe69ebbee5692c72b05071a43fc0655d8 | 3b5ab5fbe69ebbee5692c72b05071a43fc0655d8 |
| linux | linux | >= b5b5b32081cd206baa6e58cca7f112d9723785d6 < de24aceb07d426b6f1c59f33889d6a964770547b | de24aceb07d426b6f1c59f33889d6a964770547b |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.148-1 | 5.10.148-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 5.10 < 5.10.146 | 5.10.146 |
| linux | linux_kernel | >= 5.11 < 5.15.71 | 5.15.71 |
| linux | linux_kernel | >= 5.16 < 5.19.12 | 5.19.12 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-48632: In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() memcpy()
osv·2024-04-28·CVSS 7.8
CVE-2022-48632 [HIGH] CVE-2022-48632: In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() memcpy()
In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() memcpy() is called in a loop while 'operation->length' upper bound is not checked and 'data_idx' also increments.
GHSA
GHSA-54qq-rr2g-7v9v: In the Linux kernel, the following vulnerability has been resolved:
i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()
memcpy
ghsa_unreviewed·2024-04-28
CVE-2022-48632 GHSA-54qq-rr2g-7v9v: In the Linux kernel, the following vulnerability has been resolved:
i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()
memcpy
In the Linux kernel, the following vulnerability has been resolved:
i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()
memcpy() is called in a loop while 'operation->length' upper bound
is not checked and 'data_idx' also increments.
Red Hat
kernel: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()
vendor_redhat·2024-04-28·CVSS 7.8
CVE-2022-48632 [HIGH] CWE-122 kernel: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()
kernel: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()
In the Linux kernel, the following vulnerability has been resolved:
i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()
memcpy() is called in a loop while 'operation->length' upper bound
is not checked and 'data_idx' also increments.
A flaw was found in the Linux kernel. The following vulnerability has been resolved: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction().
Statement: Actual only for ARM platforms. For the Red Hat Enterprise Linux and Fedora the related code disabled, so not affected (apart from the latest version of the Red Hat Enterprise Linux 9 and latest version of the Red Hat Enterprise Linux 10). The bug could happen only if Mellanox BlueField I
Debian
CVE-2022-48632: linux - In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf:...
vendor_debian·2022·CVSS 7.8
CVE-2022-48632 [HIGH] CVE-2022-48632: linux - In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf:...
In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() memcpy() is called in a loop while 'operation->length' upper bound is not checked and 'data_idx' also increments.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resolved (fixed in 5.10.148-1)
forky: resolved (fixed in 6.0.2-1)
sid: resolved (fixed in 6.0.2-1)
trixie: resolved (fixed in 6.0.2-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/3b5ab5fbe69ebbee5692c72b05071a43fc0655d8https://git.kernel.org/stable/c/48ee0a864d1af02eea98fc825cc230d61517a71ehttps://git.kernel.org/stable/c/dc2a0c587006f29b724069740c48654b9dcaebd2https://git.kernel.org/stable/c/de24aceb07d426b6f1c59f33889d6a964770547bhttps://git.kernel.org/stable/c/3b5ab5fbe69ebbee5692c72b05071a43fc0655d8https://git.kernel.org/stable/c/48ee0a864d1af02eea98fc825cc230d61517a71ehttps://git.kernel.org/stable/c/dc2a0c587006f29b724069740c48654b9dcaebd2https://git.kernel.org/stable/c/de24aceb07d426b6f1c59f33889d6a964770547b
2024-04-28
Published