CVE-2022-49035

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 2, 2025
Updated: Jan 9, 2025
CWE ID 770

Summary

CVE-2022-49035 is a vulnerability affecting the Linux kernel's media driver, specifically the s5p_cec component. The issue involves a potential buffer overflow due to insufficient length validation of messages, which could lead to unintended code execution or system crashes. The vulnerability arises from the lack of a check to ensure messages do not exceed CEC_MAX_MSG_SIZE. This oversight could potentially be exploited if the hardware does not naturally limit message lengths to this size. The vulnerability has been resolved with appropriate length checks added to the code.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share