CVE-2022-50079

HIGH

Linux Kernel 5.14-5.14, 5.15.63-5.15.*, 5.16-5.19.4, 6.0 - Out-of-bounds Read in DCN303 Stream Encoder Instance Check

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check correct bounds for stream encoder instances for DCN303 [Why & How] eng_id for DCN303 cannot be more than 1, since we have only two instances of stream encoders. Check the correct boundary condition for engine ID for DCN303 prevent the potential out of bounds access.

Scores

CVSS v3 7.1
EPSS 0.0022
EPSS Percentile 12.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-125
Status published
Products (12)
linux/Kernel 5.14.0 - 5.15.63linux
linux/Kernel 5.16.0 - 5.19.4linux
Linux/Linux < 5.14
Linux/Linux 5.14
Linux/Linux 5.15.63 - 5.15.*
Linux/Linux 5.19.4 - 5.19.*
Linux/Linux 6.0
Linux/Linux cd6d421e3d1ad5926b74091254e345db730e7706 - 4c31dca1799612eb3b6413e3e574f90c3fb8f865
Linux/Linux cd6d421e3d1ad5926b74091254e345db730e7706 - 82a27c1855445d48aacc67b0c0640f3dadebe52f
Linux/Linux cd6d421e3d1ad5926b74091254e345db730e7706 - 89b008222c2bf21e50219725caed31590edfd9d1
... and 2 more
Published Jun 18, 2025
Tracked Since Feb 18, 2026