CVE-2022-49790

MEDIUM

Linux Kernel 5.3-5.4.225 5.5-5.10.156 5.11-5.15.80 5.16-6.0.10 - Use of Uninitialized Resource in iforce_init_device

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: Input: iforce - invert valid length check when fetching device IDs syzbot is reporting uninitialized value at iforce_init_device() [1], for commit 6ac0aec6b0a6 ("Input: iforce - allow callers supply data buffer when fetching device IDs") is checking that valid length is shorter than bytes to read. Since iforce_get_id_packet() stores valid length when returning 0, the caller needs to check that valid length is longer than or equals to bytes to read.

Scores

CVSS v3 5.5
EPSS 0.0016
EPSS Percentile 5.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-908
Status published
Products (18)
linux/Kernel 5.11.0 - 5.15.80linux
linux/Kernel 5.16.0 - 6.0.10linux
linux/Kernel 5.3.0 - 5.4.225linux
linux/Kernel 5.5.0 - 5.10.156linux
Linux/Linux < 5.3
Linux/Linux 5.10.156 - 5.10.*
Linux/Linux 5.15.80 - 5.15.*
Linux/Linux 5.3
Linux/Linux 5.4.225 - 5.4.*
Linux/Linux 6.0.10 - 6.0.*
... and 8 more
Published May 01, 2025
Tracked Since Feb 18, 2026