CVE-2022-50399
published 2025-09-18CVE-2022-50399: In the Linux kernel, the following vulnerability has been resolved: media: atomisp: prevent integer overflow in sh_css_set_black_frame() The "height" and…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
5.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
media: atomisp: prevent integer overflow in sh_css_set_black_frame()
The "height" and "width" values come from the user so the "height * width"
multiplication can overflow.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.7-1 (bookworm) | linux 6.0.7-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= a49d25364dfb9f8a64037488a39ab1f56c5fa419 < 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654 | 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654 |
| linux | linux | >= ad85094b293e40e7a2f831b0311a389d952ebd5e < a560aeac2f2d284903b5900774765d7fc61547bc | a560aeac2f2d284903b5900774765d7fc61547bc |
| linux | linux | >= ad85094b293e40e7a2f831b0311a389d952ebd5e < a549517e4b761f3940011db30320cb8c9badde54 | a549517e4b761f3940011db30320cb8c9badde54 |
| linux | linux | >= ad85094b293e40e7a2f831b0311a389d952ebd5e < 3ad290194bb06979367622e47357462836c1d3b4 | 3ad290194bb06979367622e47357462836c1d3b4 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.0.7-1 | 6.0.7-1 |
| linux | linux_kernel | >= 0 < 6.0.7-1 | 6.0.7-1 |
| linux | linux_kernel | >= 0 < 6.0.7-1 | 6.0.7-1 |
| linux | linux_kernel | >= 4.12 < 4.18 | 4.18 |
| linux | linux_kernel | >= 5.16 < 6.0.7 | 6.0.7 |
| linux | linux_kernel | >= 5.8 < 5.15.77 | 5.15.77 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: media: atomisp: prevent integer overflow in sh_css_set_black_frame()
vendor_redhat·2025-09-18·CVSS 5.5
CVE-2022-50399 [MEDIUM] kernel: media: atomisp: prevent integer overflow in sh_css_set_black_frame()
kernel: media: atomisp: prevent integer overflow in sh_css_set_black_frame()
In the Linux kernel, the following vulnerability has been resolved:
media: atomisp: prevent integer overflow in sh_css_set_black_frame()
The "height" and "width" values come from the user so the "height * width"
multiplication can overflow.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9
Debian
CVE-2022-50399: linux - In the Linux kernel, the following vulnerability has been resolved: media: atom...
vendor_debian·2022·CVSS 5.5
CVE-2022-50399 [MEDIUM] CVE-2022-50399: linux - In the Linux kernel, the following vulnerability has been resolved: media: atom...
In the Linux kernel, the following vulnerability has been resolved: media: atomisp: prevent integer overflow in sh_css_set_black_frame() The "height" and "width" values come from the user so the "height * width" multiplication can overflow.
Scope: local
bookworm: resolved (fixed in 6.0.7-1)
bullseye: open
forky: resolved (fixed in 6.0.7-1)
sid: resolved (fixed in 6.0.7-1)
trixie: resolved (fixed in 6.0.7-1)
OSV
CVE-2022-50399: In the Linux kernel, the following vulnerability has been resolved: media: atomisp: prevent integer overflow in sh_css_set_black_frame() The "height"
osv·2025-09-18·CVSS 5.5
CVE-2022-50399 [MEDIUM] CVE-2022-50399: In the Linux kernel, the following vulnerability has been resolved: media: atomisp: prevent integer overflow in sh_css_set_black_frame() The "height"
In the Linux kernel, the following vulnerability has been resolved: media: atomisp: prevent integer overflow in sh_css_set_black_frame() The "height" and "width" values come from the user so the "height * width" multiplication can overflow.
GHSA
GHSA-w9rq-5qw9-8hw2: In the Linux kernel, the following vulnerability has been resolved:
media: atomisp: prevent integer overflow in sh_css_set_black_frame()
The "height
ghsa_unreviewed·2025-09-18
CVE-2022-50399 [MEDIUM] CWE-190 GHSA-w9rq-5qw9-8hw2: In the Linux kernel, the following vulnerability has been resolved:
media: atomisp: prevent integer overflow in sh_css_set_black_frame()
The "height
In the Linux kernel, the following vulnerability has been resolved:
media: atomisp: prevent integer overflow in sh_css_set_black_frame()
The "height" and "width" values come from the user so the "height * width"
multiplication can overflow.
No detection rules found.
No public exploits indexed.
2025-09-18
Published