PT-2023-9446 · Linux+4 · Linux Kernel+4

Published

2023-01-03

·

Updated

2025-09-29

·

CVE-2022-48898

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The vulnerability is related to the dp aux cmd fifo tx() function in the Linux kernel's DP component. It is caused by synchronization errors when using a shared resource, which can lead to a race condition. This may cause the aux read transaction to return prematurely, resulting in the host's receiving buffer containing unexpected data. The issue is fixed by checking the aux isr and returning immediately at the aux isr handler if there are no isr status bits set. A bug report regarding eDP EDID corruption during system boot-up has been resolved, which was caused by the VIDEO READY interrupt continuously firing and causing dp aux isr() to complete dp aux cmd fifo tx() prematurely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2023-8447
BDU:2024-07620
CVE-2022-48898
OESA-2024-2080
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3408-1
OPENSUSE-SU-2024_3483-1
SUSE-SU-2024:3190-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3227-1
SUSE-SU-2024:3408-1
SUSE-SU-2024:3483-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Red Os
Suse