CVE-2022-50097 Details
Description
In the Linux kernel, the following vulnerability has been resolved: video: fbdev: s3fb: Check the size of screen before memset_io() In the function s3fb_set_par(), the value of 'screen_size' is calculated by the user input. If the user provides the improper value, the value of 'screen_size' may larger than 'info->screen_size', which may cause the following bug: [ 54.083733] BUG: unable to handle page fault for address: ffffc90003000000 [ 54.083742] #PF: supervisor write access in kernel mode [ 54.083744] #PF: error_code(0x0002) - not-present page [ 54.083760] RIP: 0010:memset_orig+0x33/0xb0 [ 54.083782] Call Trace: [ 54.083788] s3fb_set_par+0x1ec6/0x4040 [ 54.083806] fb_set_var+0x604/0xeb0 [ 54.083836] do_fb_ioctl+0x234/0x670 Fix the this by checking the value of 'screen_size' before memset_io().
A vulnerability in the Linux kernel's S3FB framebuffer driver can lead to memory corruption. In the function 's3fb_set_par()', the 'screen_size' value is derived from user input. If an improper value is provided, 'screen_size' may exceed 'info->screen_size', causing a page fault error. This issue arises from a lack of proper validation on the 'screen_size' before it is used, potentially leading to unauthorized memory access.
Users can apply the latest patches available in the Linux kernel Git repository to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/3c35a0dc2b4e7acf24c796043b64fa3eee799239 | kernel.org | Patch |
| https://git.kernel.org/stable/c/52461d387cc8c8f8dc40320caa2e9e101f73e7ba | kernel.org | Patch |
| https://git.kernel.org/stable/c/574912261528589012b61f82d368256247c3a5a8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5e0da18956d38e7106664dc1d06367b22f06edd3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6ba592fa014f21f35a8ee8da4ca7b95a018f13e8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ce50d94afcb8690813c5522f24cd38737657db81 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e2d7cacc6a2a1d77e7e20a492daf458a12cf19e0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/eacb50f1733660911827d7c3720f4c5425d0cdda | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.21, < 4.14.291 >= 4.15, < 4.19.256 >= 4.20, < 5.4.211 >= 5.5, < 5.10.137 >= 5.11, < 5.15.61 >= 5.16, < 5.18.18 >= 5.19, < 5.19.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Nov 19, 2025 | Initial Analysis | [email protected] |
| Jun 18, 2025 | New CVE Received | kernel.org |