Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: dsi: Prevent underflow when computing packet sizes Currently, the packet overhead is subtracted using unsigned arithmetic. With a short sync pulse, this could underflow and wrap around to near the maximal u16 value. Fix this by using signed subtraction. The call to max() will correctly handle any negative numbers that are produced. Apply the same fix to the other timings, even though those subtractions are less likely to underflow.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.18, < 5.10.138 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/82a1356a933d8443139f8886f11b63c974a09a67Patch
- https://git.kernel.org/stable/c/98e28de472ef248352f04f87e29e634ebb0ec240Patch
- https://git.kernel.org/stable/c/a1e7908f78f5a7f53f8cd83c7dcdfec974c95f26Patch
- https://git.kernel.org/stable/c/fb837f5b83461624e525727a8f4add14b201147ePatch
FAQ
What is CVE-2022-50036?
CVE-2022-50036 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: dsi: Prevent underflow when computing packet sizes Currently, the packet overhead is subtracted using unsigned arithmet...
How severe is CVE-2022-50036?
CVE-2022-50036 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-50036?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.