UBUNTU-CVE-2022-39842
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-39842
UBUNTU-CVE-2022-39842
Summary:
Details: An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third argument to copy_from_user(), a heap overflow may occur. NOTE: the original discoverer disputes that the overflow can actually happen.
References: https://ubuntu.com/security/CVE-2022-39842, https://git.kernel.org/linus/a09d2d00af53b43c6f11e6ab3cb58443c2cac8a7, https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19, https://github.com/torvalds/linux/commit/a09d2d00af53b43c6f11e6ab3cb58443c2cac8a7, https://ubuntu.com/security/notices/USN-5791-1, https://ubuntu.com/security/notices/USN-5792-1, https://ubuntu.com/security/notices/USN-5791-2, https://ubuntu.com/security/notices/USN-5792-2, https://ubuntu.com/security/notices/USN-5791-3, https://ubuntu.com/security/notices/USN-5815-1, https://ubuntu.com/security/notices/USN-5854-1, https://ubuntu.com/security/notices/USN-5861-1, https://ubuntu.com/security/notices/USN-5862-1, https://ubuntu.com/security/notices/USN-5865-1, https://ubuntu.com/security/notices/USN-5877-1, https://ubuntu.com/security/notices/USN-5883-1, https://ubuntu.com/security/notices/USN-5924-1, https://ubuntu.com/security/notices/USN-5975-1, https://ubuntu.com/security/notices/USN-6007-1, https://www.cve.org/CVERecord?id=CVE-2022-39842
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/linux-azure?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
