An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-26966.json"
[
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@e9da0b56fe27206b49f39805f7dcda8a89379062",
"target": {
"file": "drivers/net/usb/sr9700.c"
},
"id": "CVE-2022-26966-4a531694",
"digest": {
"threshold": 0.9,
"line_hashes": [
"311649817841963682764853485693526472601",
"87494280770336631771185092742324992307",
"46165333019884869820922875185722219563",
"186729589481446297198385172892779230065"
]
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@e9da0b56fe27206b49f39805f7dcda8a89379062",
"target": {
"file": "drivers/net/usb/sr9700.c",
"function": "sr9700_rx_fixup"
},
"id": "CVE-2022-26966-5bf53588",
"digest": {
"length": 852.0,
"function_hash": "32885904366830464815428385390086675841"
},
"signature_type": "Function",
"signature_version": "v1"
}
]