CVE-2022-49451
26.02.2025, 07:01
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix list protocols enumeration in the base protocol While enumerating protocols implemented by the SCMI platform using BASE_DISCOVER_LIST_PROTOCOLS, the number of returned protocols is currently validated in an improper way since the check employs a sum between unsigned integers that could overflow and cause the check itself to be silently bypassed if the returned value 'loop_num_ret' is big enough. Fix the validation avoiding the addition.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 4.17 ≤ 𝑥 < 4.19.247 |
linux | linux_kernel | 4.20 ≤ 𝑥 < 5.4.198 |
linux | linux_kernel | 5.5 ≤ 𝑥 < 5.10.121 |
linux | linux_kernel | 5.11 ≤ 𝑥 < 5.15.46 |
linux | linux_kernel | 5.16 ≤ 𝑥 < 5.17.14 |
linux | linux_kernel | 5.18 ≤ 𝑥 < 5.18.3 |
𝑥
= Vulnerable software versions

Debian Releases
References