VYPR
Medium severity6.1NVD Advisory· Published Sep 5, 2022· Updated Jun 17, 2026

CVE-2022-39842

CVE-2022-39842

Description

An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third argument to copy_from_user(), a heap overflow may occur. NOTE: the original discoverer disputes that the overflow can actually happen.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • Linux/Kernel6 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <5.19
    • cpe:2.3:o:linux:linux_kernel:5.19:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:5.19:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:5.19:rc3:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: <5.19

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.