cbcvebase.
CVE-2022-48967
published 2024-10-21

CVE-2022-48967: In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Bounds check struct nfc_target arrays While running under…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.24%
14.8th percentile
In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Bounds check struct nfc_target arrays While running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported: memcpy: detected field-spanning write (size 129) of single field "target->sensf_res" at net/nfc/nci/ntf.c:260 (size 18) This appears to be a legitimate lack of bounds checking in nci_add_new_protocol(). Add the missing checks.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < 6b37f0dc0638d13a006f2f24d2f6ca61e83bc7146b37f0dc0638d13a006f2f24d2f6ca61e83bc714
linuxlinux>= 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < dbdcfb9f6748218a149f62468d6297ce3f014e9cdbdcfb9f6748218a149f62468d6297ce3f014e9c
linuxlinux>= 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < cff35329070b96b4484d23f9f48a5ca2c947e750cff35329070b96b4484d23f9f48a5ca2c947e750
linuxlinux>= 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < 6778434706940b8fad7ef35f410d2b9929f256d26778434706940b8fad7ef35f410d2b9929f256d2
linuxlinux>= 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < 27eb2d7a1b9987b6d0429b7716b1ff3b82c4ffc927eb2d7a1b9987b6d0429b7716b1ff3b82c4ffc9
linuxlinux>= 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < 908b2da426fe9c3ce74cf541ba40e7a4251db191908b2da426fe9c3ce74cf541ba40e7a4251db191
linuxlinux>= 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < f41547546db9af99da2c34e3368664d7a79cefaef41547546db9af99da2c34e3368664d7a79cefae
linuxlinux>= 019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5 < e329e71013c9b5a4535b099208493c7826ee4a64e329e71013c9b5a4535b099208493c7826ee4a64
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.162-15.10.162-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 3.4 < 4.9.3364.9.336
linuxlinux_kernel>= 4.10 < 4.14.3024.14.302
linuxlinux_kernel>= 4.15 < 4.19.2694.19.269

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.