PT-2025-38424 · Linux+2 · Linux Kernel+2
Published
2022-10-28
·
Updated
2026-04-20
·
CVE-2022-50407
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A stack overflow issue was resolved in the crypto/hisilicon/qm module of the Linux kernel. The vulnerability occurs due to insufficient bounds checking during the use of
sscanf, potentially allowing a stack overflow when processing a qos configuration buffer. The maximum length of the qos configuration buffer is 256 bytes, while the destination buffer ('val buffer') was limited to 32 bytes. Increasing the buffer size mitigates the risk of a stack overflow identified through fuzz testing.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Uncontrolled Recursion
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linux Kernel
Hisilicon Qm