Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-48987— media: v4l2-dv-timings.c: fix too strict blanking sanity checks

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于media子系统v4l2-dv-timings.c中的过于严格的空白检查问题。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.25% · P16

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 15

VendorProduct Version RangeStatus
Linux Linux 15ded23db134da975b49ea99770de0346c193b24< 0d73b49c4037199472b29574ae21c21aef493971 affected
3d43b2b8a3cdadd6cef9ac8ef5d156b6214a01c8< a2b56627c0d13009e02f6f2c0206c0451ed19a0e affected
9cf9211635b68e8e0c8cb88d43ca7dc83e4632aa< 2572ab14b73aa45b6ae7e4c089ccf119fed5cf89 affected
b4a3a01762ae072c7f6ff2ff53b5019761288346< 4afc77068e36cee45b39d4fdc7513de26980f72c affected
683015ae163481457a16fad2317af66360dc4762< 32f01f0306a98629508f84d7ef0d1d037bc274a2 affected
491c0959f01d87bcbd5a1498bc70e0a3382c65a8< 6fb8bc29bfa80707994a63cc97e2f9920e0b0608 affected
dc7276c3f6ca008be1faf531f84b49906c9bcf7f< d3d14cdf1c7ae2caa3e999bae95ba99e955fb7c3 affected
4b6d66a45ed34a15721cb9e11492fa1a24bc83df< 5eef2141776da02772c44ec406d6871a790761ee affected
… +7 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-48987

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
media: v4l2-dv-timings.c: fix too strict blanking sanity checks
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-dv-timings.c: fix too strict blanking sanity checks Sanity checks were added to verify the v4l2_bt_timings blanking fields in order to avoid integer overflows when userspace passes weird values. But that assumed that userspace would correctly fill in the front porch, backporch and sync values, but sometimes all you know is the total blanking, which is then assigned to just one of these fields. And that can fail with these checks. So instead set a maximum for the total horizontal and vertical blanking and check that each field remains below that. That is still sufficient to avoid integer overflows, but it also allows for more flexibility in how userspace fills in these fields.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于media子系统v4l2-dv-timings.c中的过于严格的空白检查问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 15ded23db134da975b49ea99770de0346c193b24 ~ 0d73b49c4037199472b29574ae21c21aef493971 -
Linux Linux 4.9.332 ~ 4.9.336 -

II. Public POCs for CVE-2022-48987

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-48987

登录查看更多情报信息。

Patches & Fixes for CVE-2022-48987 (1)

Same Patch Batch · Linux · 2024-10-21 · 372 CVEs total

CVE-2024-50033 9.8 CRITICAL slip: make slhc_remember() more robust against malicious packets
CVE-2024-49855 9.8 CRITICAL nbd: fix race between timeout and normal completion
CVE-2024-47695 9.8 CRITICAL RDMA/rtrs-clt: Reset cid to con_num - 1 to stay in bounds
CVE-2022-48985 9.8 CRITICAL net: mana: Fix race on per-CQ variable napi work_done
CVE-2022-49003 9.8 CRITICAL nvme: fix SRCU protection of nvme_ns_head list
CVE-2024-50043 9.8 CRITICAL nfsd: fix possible badness in FREE_STATEID
CVE-2024-50047 9.8 CRITICAL smb: client: fix UAF in async decryption
CVE-2024-50046 9.8 CRITICAL NFSv4: Prevent NULL-pointer dereference in nfs42_complete_copies()
CVE-2024-49996 9.4 CRITICAL cifs: Fix buffer overflow when parsing NFS reparse points
CVE-2024-47678 9.4 CRITICAL icmp: change the order of rate limits
CVE-2022-48962 8.8 HIGH net: hisilicon: Fix potential use-after-free in hisi_femac_rx()
CVE-2024-49950 8.8 HIGH Bluetooth: L2CAP: Fix uaf in l2cap_connect
CVE-2024-49939 8.8 HIGH wifi: rtw89: avoid to add interface to list twice when SER
CVE-2022-48967 8.8 HIGH NFC: nci: Bounds check struct nfc_target arrays
CVE-2022-48964 8.8 HIGH ravb: Fix potential use-after-free in ravb_rx_gbeth()
CVE-2024-50029 8.8 HIGH Bluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync
CVE-2024-49930 8.8 HIGH wifi: ath11k: fix array out-of-bound access in SoC stats
CVE-2024-50041 8.8 HIGH i40e: Fix macvlan leak by synchronizing access to mac_filter_hash
CVE-2024-49936 8.8 HIGH net/xen-netback: prevent UAF in xenvif_flush_hash()
CVE-2022-48954 8.8 HIGH s390/qeth: fix use-after-free in hsci

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-48987

No comments yet


Leave a comment