vt_ioctl: fix array_index_nospec in vt_setactivate
Published Jul 16, 2024
7.1
HIGHCVSS 3.1
EPSS 0.31%
Description
array_index_nospec ensures that an out-of-bounds value is set to zero on the transient path. Decreasing the value by one afterwards causes a transient integer underflow. vsa.console should be decreased first and then sanitized with array_index_nospec.
Kasper Acknowledgements: Jakob Koschel, Brian Johannesmeyer, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida from the VUSec group at VU Amsterdam.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.16.62StatusaffectedConstraints<3.17
- Version 4.14.73StatusaffectedConstraints<4.14.267
- Version 4.18.11StatusaffectedConstraints<4.19
- Version 4.4.159StatusaffectedConstraints<4.5
- Version 4.9.130StatusaffectedConstraints<4.9.302
- Version
-
- Version 4.19StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.19
- Version 4.14.267StatusunaffectedConstraints<=4.14.*
- Version 4.19.230StatusunaffectedConstraints<=4.19.*
- Version 4.9.302StatusunaffectedConstraints<=4.9.*
- Version 5.10.101StatusunaffectedConstraints<=5.10.*
- Version 5.15.24StatusunaffectedConstraints<=5.15.*
- Version 5.16.10StatusunaffectedConstraints<=5.16.*
- Version 5.17StatusunaffectedConstraints<=*
- Version 5.4.180StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- < 4.9.302
- ≥ 4.10 · < 4.14.267
- ≥ 4.15 · < 4.19.320
- ≥ 4.20 · < 5.4.180
- ≥ 5.5 · < 5.10.101
- ≥ 5.11 · < 5.15.24
- ≥ 5.16 · < 5.16.10
- 5.17
- 5.17
- 5.17
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.22.1.el8_10
Fixed · RHSA-2024:7000
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
Fixed · RHSA-2024:7001
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 9.4 Extended Update Support
kernel-0:5.14.0-427.47.1.el9_4
Fixed · RHSA-2024:10771
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.22.1.el8_10 | Fixed | RHSA-2024:7000 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10 | Fixed | RHSA-2024:7001 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | kernel-0:5.14.0-427.47.1.el9_4 | Fixed | RHSA-2024:10771 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (14)
- https://access.redhat.com/security/cve/CVE-2022-48804 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2298140 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53683 Advisory
- https://git.kernel.org/stable/c/170325aba4608bde3e7d21c9c19b7bc266ac0885 Patch
- https://git.kernel.org/stable/c/2a45a6bd1e6d651770aafff57ab3e1d3bb0b42e0 Patch
- https://git.kernel.org/stable/c/61cc70d9e8ef5b042d4ed87994d20100ec8896d9 Patch
- https://git.kernel.org/stable/c/6550bdf52846f85a2a3726a5aa0c7c4399f2fc02 Patch
- https://git.kernel.org/stable/c/778302ca09498b448620edd372dc908bebf80bdf Patch
- https://git.kernel.org/stable/c/830c5aa302ec16b4ee641aec769462c37f802c90 Patch
- https://git.kernel.org/stable/c/ae3d57411562260ee3f4fd5e875f410002341104 Patch
- https://git.kernel.org/stable/c/ffe54289b02e9c732d6f04c8ebbe3b2d90d32118 Patch
- https://lore.kernel.org/linux-cve-announce/2024071645-CVE-2022-48804-f191@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48804
- https://www.cve.org/CVERecord?id=CVE-2022-48804
Change history (0)
No recorded changes yet.