In the Linux kernel, the following vulnerability has been resolved:
clk: visconti: prevent array overflow in visconti_clk_register_gates()
This code was using -1 to represent that there was no reset function.
Unfortunately, the -1 was stored in u8 so the if (clks[i].rs_id >= 0)
condition was always true. This lead to an out of bounds access in
visconti_clk_register_gates().
References
Configurations
History
17 Mar 2025, 18:57
Type | Values Removed | Values Added |
---|---|---|
References | () https://git.kernel.org/stable/c/2723543c1d60278d5aef1c4ad732dbad24b84a81 - Patch | |
References | () https://git.kernel.org/stable/c/c5601e0720ce1a3ad895f94a5838530edde01ed3 - Patch | |
CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
Summary |
|
|
CWE | CWE-129 | |
First Time |
Linux linux Kernel
Linux |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
26 Feb 2025, 07:00
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-26 07:00
Updated : 2025-03-17 18:57
NVD link : CVE-2022-49186
Mitre link : CVE-2022-49186
CVE.ORG link : CVE-2022-49186
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-129
Improper Validation of Array Index