Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - add param check for RSA Reject requests with a source buffer that is bigger than the size of the key. This is to prevent a possible integer underflow that might happen when copying the source scatterlist into a linear buffer.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 5.15.58 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/4d6d2adce08788b7667a6e58002682ea1bbf6a79Patch
- https://git.kernel.org/stable/c/9714061423b8b24b8afb31b8eb4df977c63f19c4Patch
- https://git.kernel.org/stable/c/f993321e50ba7a8ba4f5b19939e1772a921a1c42Patch
FAQ
What is CVE-2022-49563?
CVE-2022-49563 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: crypto: qat - add param check for RSA Reject requests with a source buffer that is bigger than the size of the key. This is to pre...
How severe is CVE-2022-49563?
CVE-2022-49563 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-49563?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.