CVE-2022-50719
In the Linux kernel, the following vulnerability has been resolved: ALSA: line6: fix stack overflow in line6_midi_transmit Correctly calculate available space including the size of the chunk buffer.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: line6: fix stack overflow in line6_midi_transmit Correctly calculate available space including the size of the chunk buffer. This fixes a buffer overflow when multiple MIDI sysex messages are sent to a PODxt device.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.22% probability · 13th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0c76087449ee4ed45a88b10017d02c6694caedb1
- https://git.kernel.org/stable/c/0c9118e381ff538874e00fd4e66a768273c150fb
- https://git.kernel.org/stable/c/25e8c6ecb46843a955f254b8f0d77894e4a53dc4
- https://git.kernel.org/stable/c/389d34c2a8b52acc351fd932ed4bea41fee5a39b
- https://git.kernel.org/stable/c/49cb7737e733013ec86aa77ed2e19b94a68eaa05
- https://git.kernel.org/stable/c/61e4be4a60cc6de723f8c574ddbcb3025eb44cac
- https://git.kernel.org/stable/c/66f359ad66d49f75d39ac729f9114dabf90b81bb
- https://git.kernel.org/stable/c/b026af92b2cea907c780f7168c730c816cd33311
- https://git.kernel.org/stable/c/b8800d324abb50160560c636bfafe2c81001b66c
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.