CVE-2022-49478

Updated: 2025-10-05 03:02:08.534558

Description:

In the Linux kernel, the following vulnerability has been resolved: media: pvrusb2: fix array-index-out-of-bounds in pvr2_i2c_core_init Syzbot reported that -1 is used as array index. The problem was in missing validation check. hdw->unit_number is initialized with -1 and then if init table walk fails this value remains unchanged. Since code blindly uses this member for array indexing adding sanity check is the easiest fix for that. hdw->workpoll initialization moved upper to prevent warning in __flush_work.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 6 ELS kernel 2.6.32 7.8 HIGH Released CLSA-2025:1750175787 2025-07-04 02:10:30
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2025:1749568993 2025-06-11 00:59:56
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2025:1749562017 2025-06-11 00:59:57
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Needs Triage 2025-08-30 11:23:31
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Released CLSA-2025:1750172760 2025-06-18 03:58:30
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Already Fixed 2025-04-06 03:43:55
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Released CLSA-2025:1744713316 2025-04-16 04:32:30