IT

Tracker / CVE-2022-48732

CVE-2022-48732

High 7.8

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix off by one in BIOS boundary checking Bounds checking when parsing init scripts embedded in the BIOS reject access to the last byte. This causes driver initialization to fail on Apple eMac's with GeForce 2 MX GPUs, leaving the system with no working console. This is probably only seen on OpenFirmware machines like PowerPC Macs because the BIOS image provided by OF is only the used parts of the ROM, not a power-of-two blocks read from PCI directly so PCs always have empty bytes at the end that are never accessed.

Affected products and versions

linux linux_kernel · 4.10 → 4.14.265
linux linux_kernel · 4.15 → 4.19.228
linux linux_kernel · 4.20 → 5.4.178
linux linux_kernel · 4.8 → 4.9.300
linux linux_kernel · 5.11 → 5.15.22
linux linux_kernel · 5.16 → 5.16.8
linux linux_kernel · 5.5 → 5.10.99

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References