CVE-2022-3577: High severity linux kernel vulnerability
An out-of-bounds memory write flaw was found in the Linux kernel’s Kid-friendly Wired Controller driver. This flaw allows a local user to crash or potentially escalate their privileges on the system. It is in bigbenprobe of drivers/hid/hid-bigbenff.c. The reason is incorrect assumption - bigben devices all have inputs. However, malicious devices can break this assumption, leaking to out-of-bound write.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3577?
CVE-2022-3577 has a high severity due to its potential to crash the system or escalate privileges for local users.
How do I fix CVE-2022-3577?
To fix CVE-2022-3577, update your Linux kernel to a version that is not affected by the vulnerability.
Who is affected by CVE-2022-3577?
CVE-2022-3577 affects local users running vulnerable versions of the Linux kernel with the Kid-friendly Wired Controller driver.
What type of vulnerability is CVE-2022-3577?
CVE-2022-3577 is an out-of-bounds memory write flaw found in the Linux kernel.
What are the potential impacts of CVE-2022-3577?
The potential impacts of CVE-2022-3577 include system crashes and privilege escalation for affected users.