PT-2025-38424 · Linux+2 · Linux Kernel+2

Published

2022-10-28

·

Updated

2026-04-20

·

CVE-2022-50407

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A stack overflow issue was resolved in the crypto/hisilicon/qm module of the Linux kernel. The vulnerability occurs due to insufficient bounds checking during the use of sscanf, potentially allowing a stack overflow when processing a qos configuration buffer. The maximum length of the qos configuration buffer is 256 bytes, while the destination buffer ('val buffer') was limited to 32 bytes. Increasing the buffer size mitigates the risk of a stack overflow identified through fuzz testing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Uncontrolled Recursion

Stack Overflow

Weakness Enumeration

Related Identifiers

AZL-71897
BDU:2026-02374
CVE-2022-50407

Affected Products

Debian
Linux Kernel
Hisilicon Qm