PT-2025-8545 · Linux+2 · Linux Kernel+2
Dorian Rudolph
·
Published
2022-06-09
·
Updated
2025-02-27
·
CVE-2022-49612
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been identified, related to the power supply core. The issue lies in the handling of boundary conditions by the functions
power supply temp2resist simple and power supply ocv2cap simple. Specifically, the logic for interpolation is incorrect, leading to potential out-of-bounds reads. For instance, when the ocv value exceeds the first entry in the table, high is set to -1, causing an out-of-bounds access. Additionally, the interpolation logic in temp2resist does not produce the expected results, as demonstrated by an example where a temperature of 5 should yield a resistance of 70% but instead returns 60.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Out of bounds Read
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Hat