CVE-2022-3577
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An out-of-bounds memory write flaw was found in the Linux kernel’s Kid-friendly Wired Controller driver. This flaw allows a local user to crash or potentially escalate their privileges on the system. It is in bigben_probe of drivers/hid/hid-bigbenff.c. The reason is incorrect assumption - bigben devices all have inputs. However, malicious devices can break this assumption, leaking to out-of-bound write.
Se ha encontrado un fallo de escritura en memoria fuera de límites en el Controlador con cable para Niños del kernel de Linux. Este fallo permite a un usuario local bloquear o potencialmente escalar sus privilegios en el sistema. Es encontrado en la función bigben_probe del archivo drivers/hid/hid-bigbenff.c. El motivo es una suposición incorrecta: todos los dispositivos bigben presentan entradas. Sin embargo, los dispositivos maliciosos pueden romper esta suposición, filtrando una escritura fuera de límites
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-18 CVE Reserved
- 2022-10-20 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-401: Missing Release of Memory after Effective Lifetime
- CWE-787: Out-of-bounds Write
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.20 < 5.4.198 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.20 < 5.4.198" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.5 < 5.10.121 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.5 < 5.10.121" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.11 < 5.15.46 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.11 < 5.15.46" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.16 < 5.17.14 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.16 < 5.17.14" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.18 < 5.18.3 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.18 < 5.18.3" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 5.19 Search vendor "Linux" for product "Linux Kernel" and version "5.19" | rc1 |
Affected
|