cbcvebase.
CVE-2022-48716
published 2024-06-20

CVE-2022-48716: In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd938x: fix incorrect used of portid Mixer controls have the channel id in…

PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.69%
49.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd938x: fix incorrect used of portid Mixer controls have the channel id in mixer->reg, which is not same as port id. port id should be derived from chan_info array. So fix this. Without this, its possible that we could corrupt struct wcd938x_sdw_priv by accessing port_map array out of range with channel id instead of port id.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.10-1 (bookworm)linux 5.16.10-1 (bookworm)
linuxlinux
linuxlinux>= e8ba1e05bdc016700c85fad559a812c2e795442f < aa7152f9f117b3e66b3c0d4158ca4c6d46ab229faa7152f9f117b3e66b3c0d4158ca4c6d46ab229f
linuxlinux>= e8ba1e05bdc016700c85fad559a812c2e795442f < 9167f2712dc8c24964840a4d1e2ebf130e846b959167f2712dc8c24964840a4d1e2ebf130e846b95
linuxlinux>= e8ba1e05bdc016700c85fad559a812c2e795442f < c5c1546a654f613e291a7c5d6f3660fc1eb6d0c7c5c1546a654f613e291a7c5d6f3660fc1eb6d0c7
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 5.14 < 5.15.225.15.22
linuxlinux_kernel>= 5.16 < 5.16.85.16.8
msrcazl3_kernel_6.6.78.1-3_on_azure_linux_3.0
msrccbl2_kernel_5.15.176.3-3_on_cbl_mariner_2.0

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.