We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-50221

drm/fb-helper: Fix out-of-bounds access



Description

In the Linux kernel, the following vulnerability has been resolved: drm/fb-helper: Fix out-of-bounds access Clip memory range to screen-buffer size to avoid out-of-bounds access in fbdev deferred I/O's damage handling. Fbdev's deferred I/O can only track pages. From the range of pages, the damage handler computes the clipping rectangle for the display update. If the fbdev screen buffer ends near the beginning of a page, that page could contain more scanlines. The damage handler would then track these non-existing scanlines as dirty and provoke an out-of-bounds access during the screen update. Hence, clip the maximum memory range to the size of the screen buffer. While at it, rename the variables min/max to min_off/max_off in drm_fb_helper_deferred_io(). This avoids confusion with the macros of the same name.

Reserved 2025-06-18 | Published 2025-06-18 | Updated 2025-06-18 | Assigner Linux

Product status

Default status
unaffected

67b723f5b74254d27962b1b59bddfee1584575ff before 9c49ac792c639dbec0728b513329a32461f72253
affected

67b723f5b74254d27962b1b59bddfee1584575ff before ae25885bdf59fde40726863c57fd20e4a0642183
affected

Default status
affected

5.18
affected

Any version before 5.18
unaffected

5.19.2
unaffected

6.0
unaffected

References

git.kernel.org/...c/9c49ac792c639dbec0728b513329a32461f72253

git.kernel.org/...c/ae25885bdf59fde40726863c57fd20e4a0642183

cve.org (CVE-2022-50221)

nvd.nist.gov (CVE-2022-50221)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2022-50221

Support options

Helpdesk Chat, Email, Knowledgebase