VYPR
High severity7.8NVD Advisory· Published Feb 26, 2025· Updated Jun 17, 2026

CVE-2022-49186

CVE-2022-49186

Description

In the Linux kernel, the following vulnerability has been resolved:

clk: visconti: prevent array overflow in visconti_clk_register_gates()

This code was using -1 to represent that there was no reset function. Unfortunately, the -1 was stored in u8 so the if (clks[i].rs_id >= 0) condition was always true. This lead to an out of bounds access in visconti_clk_register_gates().

Affected products

4
  • Linux/Kernel3 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.17,<5.17.2
    • (no CPE)
    • (no CPE)range: 5.17
  • osv-coords
    Range: >= 5.17.0, < 5.17.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.