CVE-2022-50440
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate the box size for the snooped cursor Invalid userspace dma surface copies could potentially overflow the memcpy from the surface to the snooped image leading to…
Does this matter?
Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate the box size for the snooped cursor Invalid userspace dma surface copies could potentially overflow the memcpy from the surface to the snooped image leading to crashes. To fix it the dimensions of the copybox have to be validated against the expected size of the snooped cursor.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.17% probability · 6th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/439cbbc1519547f9a7b483f0de33b556ebfec901Patch
- https://git.kernel.org/stable/c/4cf949c7fafe21e085a4ee386bb2dade9067316ePatch
- https://git.kernel.org/stable/c/4d54d11b49860686331c58a00f733b16a93edfc4Patch
- https://git.kernel.org/stable/c/50d177f90b63ea4138560e500d92be5e4c928186Patch
- https://git.kernel.org/stable/c/622d527decaac0eb65512acada935a0fdc1d0202Patch
- https://git.kernel.org/stable/c/6948e570f54f2044dd4da444b10471373a047eebPatch
- https://git.kernel.org/stable/c/6b4e70a428b5a11f56db94047b68e144529fe512Patch
- https://git.kernel.org/stable/c/94b283341f9f3f0ed56a360533766377a01540e0Patch
- https://git.kernel.org/stable/c/ee8d31836cbe7c26e207bfa0a4a726f0a25cfcf6Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.