cbcvebase.
CVE-2022-48717
published 2024-06-20

CVE-2022-48717: In the Linux kernel, the following vulnerability has been resolved: ASoC: max9759: fix underflow in speaker_gain_control_put() Check for negative values of…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: max9759: fix underflow in speaker_gain_control_put() Check for negative values of "priv->gain" to prevent an out of bounds access. The concern is that these might come from the user via: -> snd_ctl_elem_write_user() -> snd_ctl_elem_write() -> kctl->put()

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.10-1 (bookworm)linux 5.16.10-1 (bookworm)
linuxlinux
linuxlinux>= fa8d915172b8c10ec0734c4021e99e9705023b07 < a0f49d12547d45ea8b0f356a96632dd503941c1ea0f49d12547d45ea8b0f356a96632dd503941c1e
linuxlinux>= fa8d915172b8c10ec0734c4021e99e9705023b07 < 71e60c170105d153e34d01766c1e4db26a4b24cc71e60c170105d153e34d01766c1e4db26a4b24cc
linuxlinux>= fa8d915172b8c10ec0734c4021e99e9705023b07 < 5a45448ac95b715173edb1cd090ff24b6586d9215a45448ac95b715173edb1cd090ff24b6586d921
linuxlinux>= fa8d915172b8c10ec0734c4021e99e9705023b07 < baead410e5db49e962a67fffc17ac30e44b50b7cbaead410e5db49e962a67fffc17ac30e44b50b7c
linuxlinux>= fa8d915172b8c10ec0734c4021e99e9705023b07 < f114fd6165dfb52520755cc4d1c1dfbd447b88b6f114fd6165dfb52520755cc4d1c1dfbd447b88b6
linuxlinux>= fa8d915172b8c10ec0734c4021e99e9705023b07 < 4c907bcd9dcd233da6707059d777ab389dcbd9644c907bcd9dcd233da6707059d777ab389dcbd964
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.103-15.10.103-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 4.17 < 4.19.2284.19.228
linuxlinux_kernel>= 4.20 < 5.4.1785.4.178
linuxlinux_kernel>= 5.11 < 5.15.225.15.22
linuxlinux_kernel>= 5.16 < 5.16.85.16.8
linuxlinux_kernel>= 5.5 < 5.10.995.10.99

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.