Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Harden accesses to the reset domains Accessing reset domains descriptors by the index upon the SCMI drivers requests through the SCMI reset operations interface can potentially lead to out-of-bound violations if the SCMI driver misbehave. Add an internal consistency check before any such domains descriptors accesses.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.4, < 5.4.277 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/1f08a1b26cfc53b7715abc46857c6023bb1b87dePatch
- https://git.kernel.org/stable/c/7184491fc515f391afba23d0e9b690caaea72dafPatch
- https://git.kernel.org/stable/c/8e65edf0d37698f7a6cb174608d3ec7976baf49ePatch
- https://git.kernel.org/stable/c/e9076ffbcaed5da6c182b144ef9f6e24554af268Patch
- https://git.kernel.org/stable/c/f2277d9e2a0d092c13bae7ee82d75432bb8b5108Patch
- https://git.kernel.org/stable/c/1f08a1b26cfc53b7715abc46857c6023bb1b87dePatch
- https://git.kernel.org/stable/c/7184491fc515f391afba23d0e9b690caaea72dafPatch
- https://git.kernel.org/stable/c/8e65edf0d37698f7a6cb174608d3ec7976baf49ePatch
- https://git.kernel.org/stable/c/e9076ffbcaed5da6c182b144ef9f6e24554af268Patch
- https://git.kernel.org/stable/c/f2277d9e2a0d092c13bae7ee82d75432bb8b5108Patch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00019.htmlMailing List
- https://security.netapp.com/advisory/ntap-20240912-0008/Third Party Advisory
FAQ
What is CVE-2022-48655?
CVE-2022-48655 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Harden accesses to the reset domains Accessing reset domains descriptors by the index upon the SCMI drivers re...
How severe is CVE-2022-48655?
CVE-2022-48655 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-48655?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.