cbcvebase.
CVE-2022-48632
published 2024-04-28

CVE-2022-48632: In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() memcpy() is…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.9th percentile
In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() memcpy() is called in a loop while 'operation->length' upper bound is not checked and 'data_idx' also increments.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= b5b5b32081cd206baa6e58cca7f112d9723785d6 < 48ee0a864d1af02eea98fc825cc230d61517a71e48ee0a864d1af02eea98fc825cc230d61517a71e
linuxlinux>= b5b5b32081cd206baa6e58cca7f112d9723785d6 < dc2a0c587006f29b724069740c48654b9dcaebd2dc2a0c587006f29b724069740c48654b9dcaebd2
linuxlinux>= b5b5b32081cd206baa6e58cca7f112d9723785d6 < 3b5ab5fbe69ebbee5692c72b05071a43fc0655d83b5ab5fbe69ebbee5692c72b05071a43fc0655d8
linuxlinux>= b5b5b32081cd206baa6e58cca7f112d9723785d6 < de24aceb07d426b6f1c59f33889d6a964770547bde24aceb07d426b6f1c59f33889d6a964770547b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.148-15.10.148-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 5.10 < 5.10.1465.10.146
linuxlinux_kernel>= 5.11 < 5.15.715.15.71
linuxlinux_kernel>= 5.16 < 5.19.125.19.12

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.