Unrated severityNVD Advisory· Published Mar 15, 2022· Updated Aug 3, 2024
CVE-2022-27223
CVE-2022-27223
Description
In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.
Affected products
11- osv-coords11 versionspkg:rpm/opensuse/kernel-azure&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/kernel-source-azure&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/kernel-syms-azure&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/kernel-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP3pkg:rpm/suse/kernel-rt_debug&distro=SUSE%20Real%20Time%20Module%2015%20SP3pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/kernel-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP3pkg:rpm/suse/kernel-source-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP3pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP3pkg:rpm/suse/kernel-syms-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP3pkg:rpm/suse/kernel-syms-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP3
< 5.3.18-150300.38.53.1+ 10 more
- (no CPE)range: < 5.3.18-150300.38.53.1
- (no CPE)range: < 5.3.18-150300.38.53.1
- (no CPE)range: < 5.3.18-150300.38.53.1
- (no CPE)range: < 5.3.18-150300.38.53.1
- (no CPE)range: < 5.3.18-150300.82.1
- (no CPE)range: < 5.3.18-150300.82.1
- (no CPE)range: < 5.3.18-150300.82.1
- (no CPE)range: < 5.3.18-150300.38.53.1
- (no CPE)range: < 5.3.18-150300.82.1
- (no CPE)range: < 5.3.18-150300.38.53.1
- (no CPE)range: < 5.3.18-150300.82.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.16.12mitrex_refsource_MISC
- github.com/torvalds/linux/commit/7f14c7227f342d9932f9b918893c8814f86d2a0dmitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2022/07/msg00000.htmlmitremailing-listx_refsource_MLIST
- security.netapp.com/advisory/ntap-20220419-0001/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.