cbcvebase.
CVE-2022-49162
published 2025-02-26

CVE-2022-49162: In the Linux kernel, the following vulnerability has been resolved: video: fbdev: sm712fb: Fix crash in smtcfb_write() When the sm712fb driver writes three…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.5th percentile
In the Linux kernel, the following vulnerability has been resolved: video: fbdev: sm712fb: Fix crash in smtcfb_write() When the sm712fb driver writes three bytes to the framebuffer, the driver will crash: BUG: unable to handle page fault for address: ffffc90001ffffff RIP: 0010:smtcfb_write+0x454/0x5b0 Call Trace: vfs_write+0x291/0xd60 ? do_sys_openat2+0x27d/0x350 ? __fget_light+0x54/0x340 ksys_write+0xce/0x190 do_syscall_64+0x43/0x90 entry_SYSCALL_64_after_hwframe+0x44/0xae Fix it by removing the open-coded endianness fixup-code.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= d7edf47947f9d921be6ca5fc8e83049124466f98 < fb791514acf9070225eed46e1ccbb0aa7aae5da5fb791514acf9070225eed46e1ccbb0aa7aae5da5
linuxlinux>= d7edf47947f9d921be6ca5fc8e83049124466f98 < 0ec746674296c94137f074309c26d17e644c04980ec746674296c94137f074309c26d17e644c0498
linuxlinux>= d7edf47947f9d921be6ca5fc8e83049124466f98 < 1aea36a62f0a0ad67eccc945bac0bd6422ef720f1aea36a62f0a0ad67eccc945bac0bd6422ef720f
linuxlinux>= d7edf47947f9d921be6ca5fc8e83049124466f98 < 3b36c05f68ba32d0dfb63abc9016d6fe9117829f3b36c05f68ba32d0dfb63abc9016d6fe9117829f
linuxlinux>= d7edf47947f9d921be6ca5fc8e83049124466f98 < b1c28577529cdfad40c8242673285f1e1e4c314eb1c28577529cdfad40c8242673285f1e1e4c314e
linuxlinux>= d7edf47947f9d921be6ca5fc8e83049124466f98 < eae90015d10f0c9a47fc4adccba4cd79dce664e4eae90015d10f0c9a47fc4adccba4cd79dce664e4
linuxlinux>= d7edf47947f9d921be6ca5fc8e83049124466f98 < aeb635b49530b7d19e140949753409f759ba99beaeb635b49530b7d19e140949753409f759ba99be
linuxlinux>= d7edf47947f9d921be6ca5fc8e83049124466f98 < 809b8cde86320698661eec677222bc5c5df76176809b8cde86320698661eec677222bc5c5df76176
linuxlinux>= d7edf47947f9d921be6ca5fc8e83049124466f98 < 4f01d09b2bbfbcb47b3eb305560a7f4857a322604f01d09b2bbfbcb47b3eb305560a7f4857a32260
linuxlinux_kernel< 4.9.3114.9.311
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 4.10 < 4.14.2764.14.276
linuxlinux_kernel>= 4.15 < 4.19.2384.19.238
linuxlinux_kernel>= 4.20 < 5.4.1895.4.189
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2
linuxlinux_kernel>= 5.5 < 5.10.1105.10.110

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.