Fiche vulnérabilité
CVE-2022-48655 : faille élevée linux linux kernel (CVSS 7.8)
Description
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Harden accesses to the reset domains Accessing reset domains descriptors by the index upon the SCMI drivers requests through the SCMI reset operations interface can potentially lead to out-of-bound violations if the SCMI driver misbehave. Add an internal consistency check before any such domains descriptors accesses.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 28 avr. 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- linux linux kernel
- debian debian linux
Références
- Fiche CVE-2022-48655 sur le NVD (NIST)
- git.kernel.org/stable/c/1f08a1b26cfc53b7715abc46857c6023bb1b8…
- git.kernel.org/stable/c/7184491fc515f391afba23d0e9b690caaea72…
- git.kernel.org/stable/c/8e65edf0d37698f7a6cb174608d3ec7976baf…
- git.kernel.org/stable/c/e9076ffbcaed5da6c182b144ef9f6e24554af…
- git.kernel.org/stable/c/f2277d9e2a0d092c13bae7ee82d75432bb8b5…
- lists.debian.org/debian-lts-announce/2024/06/msg00019.html
- security.netapp.com/advisory/ntap-20240912-0008/