CVE-2022-50185 Details
Description
In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix potential buffer overflow in ni_set_mc_special_registers() The last case label can write two buffers 'mc_reg_address[j]' and 'mc_data[j]' with 'j' offset equal to SMC_NISLANDS_MC_REGISTER_ARRAY_SIZE since there are no checks for this value in both case labels after the last 'j++'. Instead of changing '>' to '>=' there, add the bounds check at the start of the second 'case' (the first one already has it). Also, remove redundant last checks for 'j' index bigger than array size. The expression is always false. Moreover, before or after the patch 'table->last' can be equal to SMC_NISLANDS_MC_REGISTER_ARRAY_SIZE and it seems it can be a valid value. Detected using the static analysis tool - Svace.
A buffer overflow vulnerability has been identified in the Linux kernel's Radeon Direct Rendering Manager (DRM) component. The issue arises in the 'ni_set_mc_special_registers()' function, where the last case label can overwrite two buffers, 'mc_reg_address[j]' and 'mc_data[j]', with an offset 'j' equal to 'SMC_NISLANDS_MC_REGISTER_ARRAY_SIZE'. This occurs because there are no checks for this value in both case labels after the last 'j++'. The vulnerability was detected using the static analysis tool Svace.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/136f614931a2bb73616b292cf542da3a18daefd5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1f341053852be76f82610ce47a505d930512f05c | kernel.org | Patch |
| https://git.kernel.org/stable/c/782e413e38dffd37cc85b08b1ccb982adb4a93ce | kernel.org | Patch |
| https://git.kernel.org/stable/c/8508d6d23a247c29792ce2fc0df3f3404d6a6a80 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9faff03617afeced1c4e5daa89e79b3906374342 | kernel.org | Patch |
| https://git.kernel.org/stable/c/db1a9add3f90ff1c641974d5bb910c16b87af4ef | kernel.org | Patch |
| https://git.kernel.org/stable/c/deb603c5928e546609c0d5798e231d0205748943 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ea73869df6ef386fc0feeb28ff66742ca835b18f | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.11, < 4.14.291 >= 4.15, < 4.19.256 >= 4.20, < 5.4.211 >= 5.5, < 5.10.137 >= 5.11, < 5.15.61 >= 5.16, < 5.18.18 >= 5.19, < 5.19.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Nov 19, 2025 | Initial Analysis | [email protected] |
| Jun 18, 2025 | New CVE Received | kernel.org |