PT-2024-11852 · Linux+4 · Linux Kernel+4

Published

2022-11-23

·

Updated

2025-09-29

·

CVE-2022-48987

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns the media component of the Linux kernel, specifically the v4l2-dv-timings.c file. It involves incorrect input validation in the v4l2 valid dv timings() function, which can lead to integer overflows when userspace passes unusual values. The problem arises when userspace only knows the total blanking and assigns it to one field, causing the sanity checks to fail. To resolve this, a maximum for the total horizontal and vertical blanking has been set, allowing for more flexibility in how userspace fills in these fields. This change is sufficient to avoid integer overflows. The exploitation of this issue may allow an attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2023-1066
BDU:2025-01679
CVE-2022-48987
OPENSUSE-SU-2024_3983-1
OPENSUSE-SU-2024_3985-1
OPENSUSE-SU-2024_4131-1
SUSE-SU-2024:3983-1
SUSE-SU-2024:3985-1
SUSE-SU-2024:4082-1
SUSE-SU-2024:4131-1
SUSE-SU-2024:4364-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Red Os
Suse