Linux Kernel Denial of Service Vulnerability in Input Drivers
CVE-2022-48619

5.5MEDIUM

Key Information:

Vendor
Linux
Vendor
CVE Published:
12 January 2024

Summary

A vulnerability affecting the Linux kernel prior to version 5.17.10 arises from an issue in the input drivers, specifically in the input.c file. The vulnerability occurs when the input_set_capability function fails to appropriately manage scenarios where an event code exists outside of an expected bitmap range. This mishandling can lead to a denial of service condition, resulting in a system panic that disrupts normal operations. Affected systems are at risk if they utilize vulnerable kernel versions, making timely updates and patches essential for maintaining security integrity.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.