CVE-2022-48732
published 2024-06-20CVE-2022-48732: In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix off by one in BIOS boundary checking Bounds checking when parsing init…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix off by one in BIOS boundary checking
Bounds checking when parsing init scripts embedded in the BIOS reject
access to the last byte. This causes driver initialization to fail on
Apple eMac's with GeForce 2 MX GPUs, leaving the system with no working
console.
This is probably only seen on OpenFirmware machines like PowerPC Macs
because the BIOS image provided by OF is only the used parts of the ROM,
not a power-of-two blocks read from PCI directly so PCs always have
empty bytes at the end that are never accessed.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.10-1 (bookworm) | linux 5.16.10-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 4d4e9907ff572bb1d1c0f6913ad6e3d6d4525077 < d4b746e60fd8eaa8016e144223abe91158edcdad | d4b746e60fd8eaa8016e144223abe91158edcdad |
| linux | linux | >= 4d4e9907ff572bb1d1c0f6913ad6e3d6d4525077 < 909d3ec1bf9f0ec534bfc081b77c0836fea7b0e2 | 909d3ec1bf9f0ec534bfc081b77c0836fea7b0e2 |
| linux | linux | >= 4d4e9907ff572bb1d1c0f6913ad6e3d6d4525077 < b2a21669ee98aafc41c6d42ef15af4dab9e6e882 | b2a21669ee98aafc41c6d42ef15af4dab9e6e882 |
| linux | linux | >= 4d4e9907ff572bb1d1c0f6913ad6e3d6d4525077 < acc887ba88333f5fec49631f12d8cc7ebd95781c | acc887ba88333f5fec49631f12d8cc7ebd95781c |
| linux | linux | >= 4d4e9907ff572bb1d1c0f6913ad6e3d6d4525077 < f071d9fa857582d7bd77f4906691f73d3edeab73 | f071d9fa857582d7bd77f4906691f73d3edeab73 |
| linux | linux | >= 4d4e9907ff572bb1d1c0f6913ad6e3d6d4525077 < d877e814a62b7de9069aeff8bc1d979dfc996e06 | d877e814a62b7de9069aeff8bc1d979dfc996e06 |
| linux | linux | >= 4d4e9907ff572bb1d1c0f6913ad6e3d6d4525077 < e7c36fa8a1e63b08312162179c78a0c7795ea369 | e7c36fa8a1e63b08312162179c78a0c7795ea369 |
| linux | linux | >= 4d4e9907ff572bb1d1c0f6913ad6e3d6d4525077 < 1b777d4d9e383d2744fc9b3a09af6ec1893c8b1a | 1b777d4d9e383d2744fc9b3a09af6ec1893c8b1a |
| linux | linux_kernel | >= 0 < 5.10.103-1 | 5.10.103-1 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 4.10 < 4.14.265 | 4.14.265 |
| linux | linux_kernel | >= 4.15 < 4.19.228 | 4.19.228 |
| linux | linux_kernel | >= 4.20 < 5.4.178 | 5.4.178 |
| linux | linux_kernel | >= 4.8 < 4.9.300 | 4.9.300 |
| linux | linux_kernel | >= 5.11 < 5.15.22 | 5.15.22 |
| linux | linux_kernel | >= 5.16 < 5.16.8 | 5.16.8 |
| linux | linux_kernel | >= 5.5 < 5.10.99 | 5.10.99 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vjh8-wgcx-46j4: In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix off by one in BIOS boundary checking
Bounds checking when parsi
ghsa_unreviewed·2024-06-20
CVE-2022-48732 [HIGH] CWE-193 GHSA-vjh8-wgcx-46j4: In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix off by one in BIOS boundary checking
Bounds checking when parsi
In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix off by one in BIOS boundary checking
Bounds checking when parsing init scripts embedded in the BIOS reject
access to the last byte. This causes driver initialization to fail on
Apple eMac's with GeForce 2 MX GPUs, leaving the system with no working
console.
This is probably only seen on OpenFirmware machines like PowerPC Macs
because the BIOS image provided by OF is only the used parts of the ROM,
not a power-of-two blocks read from PCI directly so PCs always have
empty bytes at the end that are never accessed.
OSV
CVE-2022-48732: In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix off by one in BIOS boundary checking Bounds checking when parsing
osv·2024-06-20·CVSS 7.8
CVE-2022-48732 [HIGH] CVE-2022-48732: In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix off by one in BIOS boundary checking Bounds checking when parsing
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix off by one in BIOS boundary checking Bounds checking when parsing init scripts embedded in the BIOS reject access to the last byte. This causes driver initialization to fail on Apple eMac's with GeForce 2 MX GPUs, leaving the system with no working console. This is probably only seen on OpenFirmware machines like PowerPC Macs because the BIOS image provided by OF is only the used parts of the ROM, not a power-of-two blocks read from PCI directly so PCs always have empty bytes at the end that are never accessed.
Red Hat
kernel: drm/nouveau: fix off by one in BIOS boundary checking
vendor_redhat·2024-06-20·CVSS 7.8
CVE-2022-48732 [HIGH] CWE-119 kernel: drm/nouveau: fix off by one in BIOS boundary checking
kernel: drm/nouveau: fix off by one in BIOS boundary checking
In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix off by one in BIOS boundary checking
Bounds checking when parsing init scripts embedded in the BIOS reject
access to the last byte. This causes driver initialization to fail on
Apple eMac's with GeForce 2 MX GPUs, leaving the system with no working
console.
This is probably only seen on OpenFirmware machines like PowerPC Macs
because the BIOS image provided by OF is only the used parts of the ROM,
not a power-of-two blocks read from PCI directly so PCs always have
empty bytes at the end that are never accessed.
Statement: Red Hat Product Security has evaluated the impact effects on availability as High, but no impact on Confidentiality or Inte
Debian
CVE-2022-48732: linux - In the Linux kernel, the following vulnerability has been resolved: drm/nouveau...
vendor_debian·2022·CVSS 7.8
CVE-2022-48732 [HIGH] CVE-2022-48732: linux - In the Linux kernel, the following vulnerability has been resolved: drm/nouveau...
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix off by one in BIOS boundary checking Bounds checking when parsing init scripts embedded in the BIOS reject access to the last byte. This causes driver initialization to fail on Apple eMac's with GeForce 2 MX GPUs, leaving the system with no working console. This is probably only seen on OpenFirmware machines like PowerPC Macs because the BIOS image provided by OF is only the used parts of the ROM, not a power-of-two blocks read from PCI directly so PCs always have empty bytes at the end that are never accessed.
Scope: local
bookworm: resolved (fixed in 5.16.10-1)
bullseye: resolved (fixed in 5.10.103-1)
forky: resolved (fixed in 5.16.10-1)
sid: resolved (fixed in 5.16.10-1)
trixie: resolved (fixed in 5.16.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/1b777d4d9e383d2744fc9b3a09af6ec1893c8b1ahttps://git.kernel.org/stable/c/909d3ec1bf9f0ec534bfc081b77c0836fea7b0e2https://git.kernel.org/stable/c/acc887ba88333f5fec49631f12d8cc7ebd95781chttps://git.kernel.org/stable/c/b2a21669ee98aafc41c6d42ef15af4dab9e6e882https://git.kernel.org/stable/c/d4b746e60fd8eaa8016e144223abe91158edcdadhttps://git.kernel.org/stable/c/d877e814a62b7de9069aeff8bc1d979dfc996e06https://git.kernel.org/stable/c/e7c36fa8a1e63b08312162179c78a0c7795ea369https://git.kernel.org/stable/c/f071d9fa857582d7bd77f4906691f73d3edeab73https://git.kernel.org/stable/c/1b777d4d9e383d2744fc9b3a09af6ec1893c8b1ahttps://git.kernel.org/stable/c/909d3ec1bf9f0ec534bfc081b77c0836fea7b0e2https://git.kernel.org/stable/c/acc887ba88333f5fec49631f12d8cc7ebd95781chttps://git.kernel.org/stable/c/b2a21669ee98aafc41c6d42ef15af4dab9e6e882https://git.kernel.org/stable/c/d4b746e60fd8eaa8016e144223abe91158edcdadhttps://git.kernel.org/stable/c/d877e814a62b7de9069aeff8bc1d979dfc996e06https://git.kernel.org/stable/c/e7c36fa8a1e63b08312162179c78a0c7795ea369https://git.kernel.org/stable/c/f071d9fa857582d7bd77f4906691f73d3edeab73
2024-06-20
Published