CVE-2022-49032 Details
Description
In the Linux kernel, the following vulnerability has been resolved: iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw KASAN report out-of-bounds read as follows: BUG: KASAN: global-out-of-bounds in afe4404_read_raw+0x2ce/0x380 Read of size 4 at addr ffffffffc00e4658 by task cat/278 Call Trace: afe4404_read_raw iio_read_channel_info dev_attr_show The buggy address belongs to the variable: afe4404_channel_leds+0x18/0xffffffffffffe9c0 This issue can be reproduce by singe command: $ cat /sys/bus/i2c/devices/0-0058/iio\:device0/in_intensity6_raw The array size of afe4404_channel_leds and afe4404_channel_offdacs are less than channels, so access with chan->address cause OOB read in afe4404_[read|write]_raw. Fix it by moving access before use them.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 22, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/113c08030a89aaf406f8a1d4549d758a67c2afba | kernel.org | Patch |
| https://git.kernel.org/stable/c/3f566b626029ca8598d48e5074e56bb37399ca1b | kernel.org | Patch |
| https://git.kernel.org/stable/c/5eb114f55b37dbc0487aa9c1913b81bb7837f1c4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/68de7da092f38395dde523f2e5db26eba6c23e28 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d45d9f45e7b1365fd0d9bf14680d6d5082a590d1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f5575041ec15310bdc50c42b8b22118cc900226e | kernel.org | Patch |
| https://git.kernel.org/stable/c/f7419fc42afc035f6b29ce713e17dcd2000c833f | kernel.org | Patch |
| https://git.kernel.org/stable/c/fc92d9e3de0b2d30a3ccc08048a5fad533e4672b | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.8, < 4.9.335 >= 4.10, < 4.14.301 >= 4.15, < 4.19.268 >= 4.20, < 5.4.226 >= 5.5, < 5.10.158 >= 5.11, < 5.15.82 >= 5.16, < 6.0.12 6.1 rc1 6.1 rc2 6.1 rc3 6.1 rc4 6.1 rc5 6.1 rc6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2024 | Initial Analysis | [email protected] |
| Oct 21, 2024 | New CVE Received | kernel.org |