drm/radeon: fix potential buffer overflow in ni_set_mc_special_registers()
Published Jun 18, 2025
7.8
HIGHCVSS 3.1
EPSS 0.28%
Description
The last case label can write two buffers 'mc_reg_address[j]' and 'mc_data[j]' with 'j' offset equal to SMC_NISLANDS_MC_REGISTER_ARRAY_SIZE since there are no checks for this value in both case labels after the last 'j++'.
Instead of changing '>' to '>=' there, add the bounds check at the start of the second 'case' (the first one already has it).
Also, remove redundant last checks for 'j' index bigger than array size. The expression is always false. Moreover, before or after the patch 'table->last' can be equal to SMC_NISLANDS_MC_REGISTER_ARRAY_SIZE and it seems it can be a valid value.
Detected using the static analysis tool - Svace.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 3.11
Unaffected
- ≥ 0, < 3.11
- ≥ 4.14.291, ≤ 4.14.*
- ≥ 4.19.256, ≤ 4.19.*
- ≥ 5.10.137, ≤ 5.10.*
- ≥ 5.15.61, ≤ 5.15.*
- ≥ 5.18.18, ≤ 5.18.*
- ≥ 5.19.2, ≤ 5.19.*
- ≥ 5.4.211, ≤ 5.4.*
- 6.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- ≥ 3.11 · < 4.14.291
- ≥ 4.15 · < 4.19.256
- ≥ 4.20 · < 5.4.211
- ≥ 5.5 · < 5.10.137
- ≥ 5.11 · < 5.15.61
- ≥ 5.16 · < 5.18.18
- ≥ 5.19 · < 5.19.2
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-477.10.1.el8_8
Fixed · RHSA-2023:2951
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-477.10.1.el8_8 | Fixed | RHSA-2023:2951 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2022-50185 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2373431 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55449 Advisory
- https://git.kernel.org/stable/c/136f614931a2bb73616b292cf542da3a18daefd5 Patch
- https://git.kernel.org/stable/c/1f341053852be76f82610ce47a505d930512f05c Patch
- https://git.kernel.org/stable/c/782e413e38dffd37cc85b08b1ccb982adb4a93ce Patch
- https://git.kernel.org/stable/c/8508d6d23a247c29792ce2fc0df3f3404d6a6a80 Patch
- https://git.kernel.org/stable/c/9faff03617afeced1c4e5daa89e79b3906374342 Patch
- https://git.kernel.org/stable/c/db1a9add3f90ff1c641974d5bb910c16b87af4ef Patch
- https://git.kernel.org/stable/c/deb603c5928e546609c0d5798e231d0205748943 Patch
- https://git.kernel.org/stable/c/ea73869df6ef386fc0feeb28ff66742ca835b18f Patch
- https://lore.kernel.org/linux-cve-announce/2025061834-CVE-2022-50185-b741@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50185
- https://www.cve.org/CVERecord?id=CVE-2022-50185
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data