5.5

CVE-2022-49035

media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE

In the Linux kernel, the following vulnerability has been resolved:

media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE

I expect that the hardware will have limited this to 16, but just in
case it hasn't, check for this corner case.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 4.9.333
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.299
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.265
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.224
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.154
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.78
Linux ≫ Linux Kernel Version >= 5.16 < 6.0.8
Linux ≫ Linux Kernel Version 6.1 Update rc1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.109
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://git.kernel.org/stable/c/1609231f86760c1f6a429de7913dd795b9faa08c
Patch
https://git.kernel.org/stable/c/2654e785bd4aa2439cdffbe7dc1ea30a0eddbfe4
Patch
https://git.kernel.org/stable/c/4a449430ecfb199b99ba58af63c467eb53500b39
Patch
https://git.kernel.org/stable/c/7ccb40f26cbefa1c6dfd3418bea54c9518cdbd8a
Patch
https://git.kernel.org/stable/c/93f65ce036863893c164ca410938e0968964b26c
Patch
https://git.kernel.org/stable/c/a2728bf9b6c65e46468c763e3dab7e04839d4e11
Patch
https://git.kernel.org/stable/c/cbfa26936f318b16ccf9ca31b8e8b30c0dc087bd
Patch
https://git.kernel.org/stable/c/fc0f76dd5f116fa9291327024dda392f8b4e849c
Patch