Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - add param check for DH Reject requests with a source buffer that is bigger than the size of the key. This is to prevent a possible integer underflow that might happen when copying the source scatterlist into a linear buffer.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 5.15.58 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/2acbb8771f6ac82422886e63832ee7a0f4b1635bPatch
- https://git.kernel.org/stable/c/76c9216833e7c20a67c987cf89719a3f01666aaaPatch
- https://git.kernel.org/stable/c/e7f979ed51f96495328157df663c835b17db1e30Patch
FAQ
What is CVE-2022-49564?
CVE-2022-49564 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: crypto: qat - add param check for DH Reject requests with a source buffer that is bigger than the size of the key. This is to prev...
How severe is CVE-2022-49564?
CVE-2022-49564 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-49564?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.