CVE-2022-48739

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-48739
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48739.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-48739
Downstream
Related
Published
2024-06-20T11:13:24Z
Modified
2025-10-08T06:40:08.011333Z
Summary
ASoC: hdmi-codec: Fix OOB memory accesses
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: hdmi-codec: Fix OOB memory accesses

Correct size of iecstatus array by changing it to the size of status array of the struct sndaes_iec958. This fixes out-of-bounds slab read accesses made by memcpy() of the hdmi-codec driver. This problem is reported by KASAN.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7a8e1d44211e16eb394b7b9e0b236ee1503a3ad3
Fixed
10007bd96b6c4c3cfaea9e76c311b06a07a5e260
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7a8e1d44211e16eb394b7b9e0b236ee1503a3ad3
Fixed
1552e66be325a21d7eff49f46013fb402165a0ac
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7a8e1d44211e16eb394b7b9e0b236ee1503a3ad3
Fixed
06feec6005c9d9500cd286ec440aabf8b2ddd94d

Affected versions

v5.*

v5.13
v5.13-rc2
v5.13-rc3
v5.13-rc4
v5.13-rc5
v5.13-rc6
v5.13-rc7
v5.14
v5.14-rc1
v5.14-rc2
v5.14-rc3
v5.14-rc4
v5.14-rc5
v5.14-rc6
v5.14-rc7
v5.15
v5.15-rc1
v5.15-rc2
v5.15-rc3
v5.15-rc4
v5.15-rc5
v5.15-rc6
v5.15-rc7
v5.15.1
v5.15.10
v5.15.11
v5.15.12
v5.15.13
v5.15.14
v5.15.15
v5.15.16
v5.15.17
v5.15.18
v5.15.19
v5.15.2
v5.15.20
v5.15.21
v5.15.3
v5.15.4
v5.15.5
v5.15.6
v5.15.7
v5.15.8
v5.15.9
v5.16
v5.16-rc1
v5.16-rc2
v5.16-rc3
v5.16-rc4
v5.16-rc5
v5.16-rc6
v5.16-rc7
v5.16-rc8
v5.16.1
v5.16.2
v5.16.3
v5.16.4
v5.16.5
v5.16.6
v5.16.7

Database specific

{
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "149087336448597391325586982423579975407",
                    "154405903599300784552048137194788175246",
                    "308939331236430135279933064179864215927",
                    "120522038495798653836565276417356579496",
                    "230152433643914267044022565762712040429"
                ]
            },
            "id": "CVE-2022-48739-19f3ef0c",
            "deprecated": false,
            "target": {
                "file": "include/uapi/sound/asound.h"
            },
            "signature_type": "Line",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@06feec6005c9d9500cd286ec440aabf8b2ddd94d"
        },
        {
            "signature_version": "v1",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "72154775924526091814762006611138739595",
                    "31147388564322589729414010249389350109",
                    "21629429856566331115879567678439538412",
                    "214685529716776870552441483981106245224"
                ]
            },
            "id": "CVE-2022-48739-201ca807",
            "deprecated": false,
            "target": {
                "file": "sound/soc/codecs/hdmi-codec.c"
            },
            "signature_type": "Line",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@06feec6005c9d9500cd286ec440aabf8b2ddd94d"
        },
        {
            "signature_version": "v1",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "72154775924526091814762006611138739595",
                    "31147388564322589729414010249389350109",
                    "21629429856566331115879567678439538412",
                    "214685529716776870552441483981106245224"
                ]
            },
            "id": "CVE-2022-48739-26400f5e",
            "deprecated": false,
            "target": {
                "file": "sound/soc/codecs/hdmi-codec.c"
            },
            "signature_type": "Line",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@10007bd96b6c4c3cfaea9e76c311b06a07a5e260"
        },
        {
            "signature_version": "v1",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "149087336448597391325586982423579975407",
                    "154405903599300784552048137194788175246",
                    "308939331236430135279933064179864215927",
                    "120522038495798653836565276417356579496",
                    "230152433643914267044022565762712040429"
                ]
            },
            "id": "CVE-2022-48739-9c6dd00e",
            "deprecated": false,
            "target": {
                "file": "include/uapi/sound/asound.h"
            },
            "signature_type": "Line",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@10007bd96b6c4c3cfaea9e76c311b06a07a5e260"
        },
        {
            "signature_version": "v1",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "149087336448597391325586982423579975407",
                    "154405903599300784552048137194788175246",
                    "308939331236430135279933064179864215927",
                    "120522038495798653836565276417356579496",
                    "230152433643914267044022565762712040429"
                ]
            },
            "id": "CVE-2022-48739-9dcb2d4a",
            "deprecated": false,
            "target": {
                "file": "include/uapi/sound/asound.h"
            },
            "signature_type": "Line",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1552e66be325a21d7eff49f46013fb402165a0ac"
        },
        {
            "signature_version": "v1",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "72154775924526091814762006611138739595",
                    "31147388564322589729414010249389350109",
                    "21629429856566331115879567678439538412",
                    "214685529716776870552441483981106245224"
                ]
            },
            "id": "CVE-2022-48739-f27ddcaf",
            "deprecated": false,
            "target": {
                "file": "sound/soc/codecs/hdmi-codec.c"
            },
            "signature_type": "Line",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1552e66be325a21d7eff49f46013fb402165a0ac"
        }
    ]
}

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
5.15.22
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.16.8