CVE-2022-48672

HIGH

Linux kernel - Buffer Overflow

Title source: llm

Description

In the Linux kernel, the following vulnerability has been resolved: of: fdt: fix off-by-one error in unflatten_dt_nodes() Commit 78c44d910d3e ("drivers/of: Fix depth when unflattening devicetree") forgot to fix up the depth check in the loop body in unflatten_dt_nodes() which makes it possible to overflow the nps[] buffer... Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 4.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-193
Status published

Affected Products (7)

linux/linux_kernel < 4.14.295
linux/Kernel < 4.14.295linux
linux/Kernel < 4.19.260linux
linux/Kernel < 5.4.215linux
linux/Kernel < 5.10.145linux
linux/Kernel < 5.15.70linux
linux/Kernel < 5.19.11linux

Timeline

Published May 03, 2024
Tracked Since Feb 18, 2026