CVE-2022-48630

    Dashboard / Vulnerabilities / CVE-2022-48630

    CVE-2022-48630

    Published: 5 Mar 2024Last Modified: 8 Oct 2026

    Summary: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ

    Details: In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commit referenced in the Fixes tag removed the 'break' from the else branch in qcom_rng_read(), causing an infinite loop whenever 'max' is not a multiple of WORD_SZ. This can be reproduced e.g. by running: kcapi-rng -b 67 >/dev/null There are many ways to fix this without adding back the 'break', but they all seem more awkward than simply adding it back, so do just that. Tested on a machine with Qualcomm Amberwing processor.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- a8e32bbb96c25b7ab29b1894dcd45e0b3b08fd9d

    Affected versions

    v4.19.244
    v4.19.243
    v4.19.242
    v4.19.241
    v4.19.240
    v4.19.239
    v4.19.238
    v4.19.237
    v4.19.236

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-48630 | CVE-DB