cbcvebase.
CVE-2022-50325
published 2025-09-15

CVE-2022-50325: In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Fix potential RX buffer overflow If an event caused firmware to return…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.3th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Fix potential RX buffer overflow If an event caused firmware to return invalid RX size for LARGE_CONFIG_GET, memcpy_fromio() could end up copying too many bytes. Fix by utilizing min_t().

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= f14a1c5a9f830025dc8638303ddefd5f731ae4bc < ec1f0c12cb2e614c3fa8e9402f7ffcf82166078aec1f0c12cb2e614c3fa8e9402f7ffcf82166078a
linuxlinux>= f14a1c5a9f830025dc8638303ddefd5f731ae4bc < 0bad12fee5ae16ab439d97c66c4238f5f4cc7f680bad12fee5ae16ab439d97c66c4238f5f4cc7f68
linuxlinux>= f14a1c5a9f830025dc8638303ddefd5f731ae4bc < 23ae34e033b2c0e5e88237af82b163b296fd6aa923ae34e033b2c0e5e88237af82b163b296fd6aa9
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 5.18 < 6.0.166.0.16
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.