Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-48987— media: v4l2-dv-timings.c: fix too strict blanking sanity checks

AI Predicted 5.5 Difficulty: Moderate EPSS 0.25% · P16

Affected Version Matrix 15

VendorProductVersion RangeStatus
LinuxLinux15ded23db134da975b49ea99770de0346c193b24< 0d73b49c4037199472b29574ae21c21aef493971affected
3d43b2b8a3cdadd6cef9ac8ef5d156b6214a01c8< a2b56627c0d13009e02f6f2c0206c0451ed19a0eaffected
9cf9211635b68e8e0c8cb88d43ca7dc83e4632aa< 2572ab14b73aa45b6ae7e4c089ccf119fed5cf89affected
b4a3a01762ae072c7f6ff2ff53b5019761288346< 4afc77068e36cee45b39d4fdc7513de26980f72caffected
683015ae163481457a16fad2317af66360dc4762< 32f01f0306a98629508f84d7ef0d1d037bc274a2affected
491c0959f01d87bcbd5a1498bc70e0a3382c65a8< 6fb8bc29bfa80707994a63cc97e2f9920e0b0608affected
dc7276c3f6ca008be1faf531f84b49906c9bcf7f< d3d14cdf1c7ae2caa3e999bae95ba99e955fb7c3affected
4b6d66a45ed34a15721cb9e11492fa1a24bc83df< 5eef2141776da02772c44ec406d6871a790761eeaffected
… +7 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-48987

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
media: v4l2-dv-timings.c: fix too strict blanking sanity checks
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-dv-timings.c: fix too strict blanking sanity checks Sanity checks were added to verify the v4l2_bt_timings blanking fields in order to avoid integer overflows when userspace passes weird values. But that assumed that userspace would correctly fill in the front porch, backporch and sync values, but sometimes all you know is the total blanking, which is then assigned to just one of these fields. And that can fail with these checks. So instead set a maximum for the total horizontal and vertical blanking and check that each field remains below that. That is still sufficient to avoid integer overflows, but it also allows for more flexibility in how userspace fills in these fields.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于media子系统v4l2-dv-timings.c中的过于严格的空白检查问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 15ded23db134da975b49ea99770de0346c193b24 ~ 0d73b49c4037199472b29574ae21c21aef493971 -
LinuxLinux 4.9.332 ~ 4.9.336 -

II. Public POCs for CVE-2022-48987

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-48987

登录查看更多情报信息。

Patches & Fixes for CVE-2022-48987 (1)

Same Patch Batch · Linux · 2024-10-21 · 372 CVEs total

CVE-2024-50017x86/mm/ident_map: Use gbpages only where full GB page should be mapped.
CVE-2024-50028thermal: core: Reference count the zone in thermal_zone_get_by_id()
CVE-2024-50029Bluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync
CVE-2024-50027thermal: core: Free tzp copy along with the thermal zone
CVE-2024-50025scsi: fnic: Move flush_work initialization out of if block
CVE-2024-50026scsi: wd33c93: Don't use stale scsi_pointer value
CVE-2024-50023net: phy: Remove LED entry from LEDs list on unregister
CVE-2024-50024net: Fix an unsafe loop on the list
CVE-2024-50022device-dax: correct pgoff align in dax_set_mapping()
CVE-2024-50021ice: Fix improper handling of refcount in ice_dpll_init_rclk_pins()
CVE-2024-50020ice: Fix improper handling of refcount in ice_sriov_set_msix_vec_count()
CVE-2024-50019kthread: unpark only parked kthread
CVE-2024-50010exec: don't WARN for racy path_noexec check
CVE-2024-50005mac802154: Fix potential RCU dereference issue in mac802154_scan_worker
CVE-2024-50006ext4: fix i_data_sem unlock order in ext4_ind_migrate()
CVE-2024-50007ALSA: asihpi: Fix potential OOB array access
CVE-2024-50008wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_cmd_802_11_scan_ext()
CVE-2024-50009cpufreq: amd-pstate: add check for cpufreq_cpu_get's return value
CVE-2024-50013exfat: fix memory leak in exfat_load_bitmap()
CVE-2024-50015ext4: dax: fix overflowing extents beyond inode size when partially writing

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-48987

No comments yet


Leave a comment