An issue was discovered in drivers/input/input.c in the Linux kernel before 5.17.10. An attacker can cause a denial of service (panic) because inputsetcapability mishandles the situation in which an event code falls outside of a bitmap.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48619.json"
[
{
"target": {
"file": "drivers/input/input.c"
},
"digest": {
"line_hashes": [
"296907170608861576310502759690905796150",
"23576868401508027197633147685690573559",
"98144552058244141385054271847113321201",
"23213500495233280001644142895321544164",
"105812302915062679344874170157128792542",
"85661402702976431913021203280679022928",
"216544845681047586836767212958977891519"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "CVE-2022-48619-99b0a4f0",
"source": "https://github.com/torvalds/linux/commit/409353cbe9fe48f6bc196114c442b1cff05a39bc",
"deprecated": false,
"signature_version": "v1"
},
{
"target": {
"file": "drivers/input/input.c",
"function": "input_set_capability"
},
"digest": {
"length": 778.0,
"function_hash": "83330534483626913348331012224457818386"
},
"signature_type": "Function",
"id": "CVE-2022-48619-9d0d9f4d",
"source": "https://github.com/torvalds/linux/commit/409353cbe9fe48f6bc196114c442b1cff05a39bc",
"deprecated": false,
"signature_version": "v1"
}
]