PT-2025-25872 · Linux+2 · Linux Kernel+2

Published

2022-08-23

·

Updated

2025-07-28

·

CVE-2022-49946

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, specifically in the clk: bcm: rpi component. The issue arises from a while loop in the raspberrypi discover clocks() function that assumes the id of the last clock element is zero. However, since this data comes from the Videocore firmware, which does not guarantee such behavior, it could lead to out-of-bounds access. The fix involves providing a sentinel element to prevent this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02653
CVE-2022-49946
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Linux Kernel
Suse