cbcvebase.
CVE-2022-48948
published 2024-10-21

CVE-2022-48948: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: Prevent buffer overflow in setup handler Setup function…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.0th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: Prevent buffer overflow in setup handler Setup function uvc_function_setup permits control transfer requests with up to 64 bytes of payload (UVC_MAX_REQUEST_SIZE), data stage handler for OUT transfer uses memcpy to copy req->actual bytes to uvc_event->data.data array of size 60. This may result in an overflow of 4 bytes.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= cdda479f15cd13fa50a913ca85129c0437cc7b91 < 4972e3528b968665b596b5434764ff8fd9446d354972e3528b968665b596b5434764ff8fd9446d35
linuxlinux>= cdda479f15cd13fa50a913ca85129c0437cc7b91 < 06fd17ee92c8f1704c7e54ec0fd50ae0542a49a506fd17ee92c8f1704c7e54ec0fd50ae0542a49a5
linuxlinux>= cdda479f15cd13fa50a913ca85129c0437cc7b91 < bc8380fe5768c564f921f7b4eaba932e330b9e4bbc8380fe5768c564f921f7b4eaba932e330b9e4b
linuxlinux>= cdda479f15cd13fa50a913ca85129c0437cc7b91 < b8fb1cba934ea122b50f13a4f9d6fc4fdc43d2beb8fb1cba934ea122b50f13a4f9d6fc4fdc43d2be
linuxlinux>= cdda479f15cd13fa50a913ca85129c0437cc7b91 < c79538f32df12887f110dcd6b9c825b482905f24c79538f32df12887f110dcd6b9c825b482905f24
linuxlinux>= cdda479f15cd13fa50a913ca85129c0437cc7b91 < 6b41a35b41f77821db24f2d8f66794b390a585c56b41a35b41f77821db24f2d8f66794b390a585c5
linuxlinux>= cdda479f15cd13fa50a913ca85129c0437cc7b91 < 7b1f773277a72f9756d47a41b94e43506cce19547b1f773277a72f9756d47a41b94e43506cce1954
linuxlinux>= cdda479f15cd13fa50a913ca85129c0437cc7b91 < d1a92bb8d697f170d93fe922da763d7d156b8841d1a92bb8d697f170d93fe922da763d7d156b8841
linuxlinux>= cdda479f15cd13fa50a913ca85129c0437cc7b91 < 4c92670b16727365699fe4b19ed32013bab2c1074c92670b16727365699fe4b19ed32013bab2c107
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.162-15.10.162-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 2.6.35 < 4.9.3374.9.337
linuxlinux_kernel>= 4.10 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.855.15.85
linuxlinux_kernel>= 5.16 < 6.0.156.0.15
linuxlinux_kernel>= 5.5 < 5.10.1615.10.161

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.