CVE-2022-48866

Updated: 2024-11-30 04:24:30.324799

Description:

In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: fix OOB read in thrustmaster_interrupts Syzbot reported an slab-out-of-bounds Read in thrustmaster_probe() bug. The root case is in missing validation check of actual number of endpoints. Code should not blindly access usb_host_interface::endpoint array, since it may contain less endpoints than code expects. Fix it by adding missing validaion check and print an error if number of endpoints do not match expected number


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.1000000000000005

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.1 HIGH Already Fixed 2024-10-04 05:27:07
CentOS 6 ELS kernel 2.6.32 7.1 HIGH Not Vulnerable 2024-09-24 14:23:39
CentOS 7 ELS kernel 3.10.0 7.1 HIGH Not Vulnerable 2024-09-24 14:23:39
CentOS 8.4 ELS kernel 4.18.0 7.1 HIGH Not Vulnerable 2024-09-24 14:23:39
CentOS 8.5 ELS kernel 4.18.0 7.1 HIGH Not Vulnerable 2024-09-24 14:23:39
CentOS Stream 8 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2024:1727815919 2024-10-01 17:27:24
CloudLinux 6 ELS kernel 2.6.32 7.1 HIGH Not Vulnerable 2024-09-24 14:23:39
CloudLinux 7 ELS kernel 3.10.0 7.1 HIGH Not Vulnerable 2024-09-24 14:23:39
Oracle Linux 6 ELS kernel 2.6.32 7.1 HIGH Not Vulnerable 2024-09-24 14:23:39