First published: Tue Mar 15 2022(Updated: )
In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=3.18<4.9.304 | |
Linux Kernel | >=4.10<4.14.269 | |
Linux Kernel | >=4.15<4.19.232 | |
Linux Kernel | >=4.20<5.4.182 | |
Linux Kernel | >=5.5<5.10.103 | |
Linux Kernel | >=5.11<5.15.26 | |
Linux Kernel | >=5.16<5.16.12 | |
NetApp Active IQ Unified Manager | ||
All of | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
All of | ||
NetApp H700S | ||
NetApp H700S | ||
All of | ||
NetApp H300E | ||
NetApp H300E Firmware | ||
All of | ||
NetApp H500S Firmware | ||
NetApp H500e Firmware | ||
All of | ||
NetApp H700E | ||
NetApp H700E | ||
All of | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
All of | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
Debian Linux | =9.0 | |
Linux Kernel | <5.16.12 | |
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
NetApp H700S | ||
NetApp H700S | ||
NetApp H300E | ||
NetApp H300E Firmware | ||
NetApp H500S Firmware | ||
NetApp H500e Firmware | ||
NetApp H700E | ||
NetApp H700E | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.20-1 6.12.21-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27223 is considered a potential security vulnerability due to an endpoint index being unvalidated.
To fix CVE-2022-27223, it is recommended to upgrade to Linux kernel version 5.16.12 or a later version.
CVE-2022-27223 affects various versions of the Linux kernel prior to 5.16.12.
Yes, CVE-2022-27223 can potentially be exploited by attackers with host access.
CVE-2022-27223 can lead to out-of-array access, which could compromise system integrity and availability.