High severity8.8NVD Advisory· Published Mar 16, 2022· Updated Jun 17, 2026
CVE-2022-27223
CVE-2022-27223
Description
In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
22- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
- cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
- osv-coords11 versionspkg:rpm/suse/kernel-rt_debug&distro=SUSE%20Real%20Time%20Module%2015%20SP3pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP3pkg:rpm/suse/kernel-syms-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP3pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/kernel-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP3pkg:rpm/suse/kernel-source-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP3pkg:rpm/suse/kernel-syms-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP3pkg:rpm/opensuse/kernel-azure&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/kernel-source-azure&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/kernel-syms-azure&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/kernel-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP3
< 5.3.18-150300.82.1+ 10 more
- (no CPE)range: < 5.3.18-150300.82.1
- (no CPE)range: < 5.3.18-150300.82.1
- (no CPE)range: < 5.3.18-150300.82.1
- (no CPE)range: < 5.3.18-150300.82.1
- (no CPE)range: < 5.3.18-150300.38.53.1
- (no CPE)range: < 5.3.18-150300.38.53.1
- (no CPE)range: < 5.3.18-150300.38.53.1
- (no CPE)range: < 5.3.18-150300.38.53.1
- (no CPE)range: < 5.3.18-150300.38.53.1
- (no CPE)range: < 5.3.18-150300.38.53.1
- (no CPE)range: < 5.3.18-150300.82.1
Patches
Vulnerability mechanics
References
4- github.com/torvalds/linux/commit/7f14c7227f342d9932f9b918893c8814f86d2a0dnvdPatchThird Party Advisory
- cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.16.12nvdMailing ListRelease NotesVendor Advisory
- lists.debian.org/debian-lts-announce/2022/07/msg00000.htmlnvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20220419-0001/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.