PT-2024-11888 · Linux+4 · Linux Kernel+4

Wei Yongjun

·

Published

2022-11-12

·

Updated

2025-09-29

·

CVE-2022-49031

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability has been resolved in the Linux kernel, specifically in the iio: health: afe4403 module. The issue is an out-of-bounds read in the afe4403 read raw function. The KASAN report indicates a global-out-of-bounds read at address ffffffffc02ac638. The call trace shows that the issue occurs in the afe4403 read raw, iio read channel info, and dev attr show functions. The array size of afe4403 channel leds is less than the number of channels, causing an out-of-bounds read when accessing chan->address. This issue can be reproduced by running the command $ cat /sys/bus/spi/devices/spi0.0/iio:device0/in intensity6 raw.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2023-1066
BDU:2025-01985
CVE-2022-49031
OESA-2024-2370
OESA-2024-2371
OPENSUSE-SU-2024_3983-1
OPENSUSE-SU-2024_3985-1
OPENSUSE-SU-2024_4131-1
OPENSUSE-SU-2024_4313-1
SUSE-SU-2024:3983-1
SUSE-SU-2024:3985-1
SUSE-SU-2024:4082-1
SUSE-SU-2024:4131-1
SUSE-SU-2024:4313-1
SUSE-SU-2024:4317-1
SUSE-SU-2024:4364-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Red Os
Suse