cbcvebase.
CVE-2022-48866
published 2024-07-16

CVE-2022-48866: In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: fix OOB read in thrustmaster_interrupts Syzbot reported an…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.27%
18.9th percentile
In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: fix OOB read in thrustmaster_interrupts Syzbot reported an slab-out-of-bounds Read in thrustmaster_probe() bug. The root case is in missing validation check of actual number of endpoints. Code should not blindly access usb_host_interface::endpoint array, since it may contain less endpoints than code expects. Fix it by adding missing validaion check and print an error if number of endpoints do not match expected number

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.18-1 (bookworm)linux 5.16.18-1 (bookworm)
linuxlinux
linuxlinux>= c49c33637802a2c6957a78119eb8be3b055dd9e9 < 3ffbe85cda7f523dad896bae08cecd8db8b555ab3ffbe85cda7f523dad896bae08cecd8db8b555ab
linuxlinux>= c49c33637802a2c6957a78119eb8be3b055dd9e9 < 56185434e1e50acecee56d8f5850135009b8794756185434e1e50acecee56d8f5850135009b87947
linuxlinux>= c49c33637802a2c6957a78119eb8be3b055dd9e9 < fc3ef2e3297b3c0e2006b5d7b3d66965e3392036fc3ef2e3297b3c0e2006b5d7b3d66965e3392036
linuxlinux_kernel>= 0 < 5.16.18-15.16.18-1
linuxlinux_kernel>= 0 < 5.16.18-15.16.18-1
linuxlinux_kernel>= 0 < 5.16.18-15.16.18-1
linuxlinux_kernel>= 5.13 < 5.15.295.15.29
linuxlinux_kernel>= 5.16 < 5.16.155.16.15

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.