目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2022-48927— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.22% · P12

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 8

ベンダープロダクトVersion Rangeステータス
LinuxLinux9374e8f5a38defe90bc65b2decf317c1c62d91dd< 0cb9b2f73c182d242a640e512f4785c7c504512faffected
9374e8f5a38defe90bc65b2decf317c1c62d91dd< 082d2c047b0d305bb0b6e9f9d671a09470e2db2daffected
9374e8f5a38defe90bc65b2decf317c1c62d91dd< b7a78a8adaa8849c02f174d707aead0f85dca0daaffected
5.14affected
< 5.14unaffected
5.15.26≤ 5.15.*unaffected
5.16.12≤ 5.16.*unaffected
5.17≤ *unaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2022-48927の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
iio: adc: tsc2046: fix memory corruption by preventing array overflow
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: iio: adc: tsc2046: fix memory corruption by preventing array overflow On one side we have indio_dev->num_channels includes all physical channels + timestamp channel. On other side we have an array allocated only for physical channels. So, fix memory corruption by ARRAY_SIZE() instead of num_channels variable. Note the first case is a cleanup rather than a fix as the software timestamp channel bit in active_scanmask is never set by the IIO core.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于使用了错误的变量导致存在数组越界问题。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 9374e8f5a38defe90bc65b2decf317c1c62d91dd ~ 0cb9b2f73c182d242a640e512f4785c7c504512f -
LinuxLinux 5.14 -

II. CVE-2022-48927の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2022-48927のインテリジェンス情報

登录查看更多情报信息。

CVE-2022-48927 其他参考 (3)

Same Patch Batch · Linux · 2024-08-22 · 42 CVEs total

CVE-2022-489418.8 HIGHice: fix concurrent reset and removal of VFs
CVE-2022-489198.8 HIGHcifs: fix double free race when mount fails in cifs_get_root()
CVE-2022-489237.8 HIGHbtrfs: prevent copying too big compressed lzo segment
CVE-2022-489257.8 HIGHRDMA/cma: Do not change route.addr.src_addr outside state checks
CVE-2022-489137.8 HIGHblktrace: fix use after free for struct blk_trace
CVE-2022-489127.8 HIGHnetfilter: fix use-after-free in __nf_register_net_hook()
CVE-2022-489117.8 HIGHnetfilter: nf_queue: fix possible use-after-free
CVE-2022-489327.8 HIGHnet/mlx5: DR, Fix slab-out-of-bounds in mlx5_cmd_dr_create_fte
CVE-2022-489357.8 HIGHnetfilter: nf_tables: unregister flowtable hooks on netns exit
CVE-2022-489407.8 HIGHbpf: Fix crash due to incorrect copy_map_value
CVE-2022-489437.1 HIGHKVM: x86/mmu: make apf token non-zero to fix bug
CVE-2022-48933netfilter: nf_tables: fix memory leak during stateful obj update
CVE-2022-48934nfp: flower: Fix a potential leak in nfp_tunnel_add_shared_mac()
CVE-2022-48931configfs: fix a race in configfs_{,un}register_subsystem()
CVE-2022-48937io_uring: add a schedule point in io_add_buffers()
CVE-2022-48938CDC-NCM: avoid overflow in sanity checking
CVE-2022-48930RDMA/ib_srp: Fix a deadlock
CVE-2022-48929bpf: Fix crash due to out of bounds access into reg2btf_ids.
CVE-2022-48928iio: adc: men_z188_adc: Fix a resource leak in an error handling path
CVE-2022-48926usb: gadget: rndis: add spinlock for rndis response list

Showing 20 of 42 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2022-48927へのコメント

まだコメントはありません


コメントを残す