Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2022-48630— crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于crypto qcom-rng中存在无限循环。

AI Predicted 4.0 Difficulty: Moderate EPSS 0.23% · P12

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux a8e32bbb96c25b7ab29b1894dcd45e0b3b08fd9d< 71a89789552b7faf3ef27969b9bc783fa0df3550 affected
184f7bd08ce56f003530fc19f160d54e75bf5c9d< 8be06f62b426801dba43ddf8893952a0e62ab6ae affected
0f9b7b8df17525e464294c916acc8194ce38446b< 233a3cc60e7a8fe0be8cf9934ae7b67ba25a866c affected
ab9337c7cb6f875b6286440b1adfbeeef2b2b2bd< 8a06f25f5941c145773204f2f7abef95b4ffb8ce affected
a680b1832ced3b5fa7c93484248fd221ea0d614b< 05d4d17475d8d094c519bb51658bc47899c175e3 affected
a680b1832ced3b5fa7c93484248fd221ea0d614b< 16287397ec5c08aa58db6acf7dbc55470d78087d affected
485995cbc98a4f77cfd4f8ed4dd7ff8ab262964d affected
4.19.236< 4.19.245 affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-48630

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commit referenced in the Fixes tag removed the 'break' from the else branch in qcom_rng_read(), causing an infinite loop whenever 'max' is not a multiple of WORD_SZ. This can be reproduced e.g. by running: kcapi-rng -b 67 >/dev/null There are many ways to fix this without adding back the 'break', but they all seem more awkward than simply adding it back, so do just that. Tested on a machine with Qualcomm Amberwing processor.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于crypto qcom-rng中存在无限循环。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux a8e32bbb96c25b7ab29b1894dcd45e0b3b08fd9d ~ 71a89789552b7faf3ef27969b9bc783fa0df3550 -
Linux Linux 5.17 -

II. Public POCs for CVE-2022-48630

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-48630

请登录查看更多情报信息。

Other References for CVE-2022-48630 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2022-48630

No comments yet


Leave a comment