ASoC: tas2562: Validate values for volume writes
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
ASoC: tas2562: Validate values for volume writes
tas2562_volume_control_put() does not do any validation of the control
value written by userspace, it uses it to look up a value in a fixed
size array which can easily be overflowed and then writes whatever value
it gets back to the device. Add validation that we are loading a value
we have in the array.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/1f389ecd0c35e9e281036e44c121df904f3164c1https://git.kernel.org/stable/c/20bdbb1376457ecbf418bf677fd285820d1fc011https://git.kernel.org/stable/c/8fb41964f7e4e4207c8999af2056894caa7a252ahttps://git.kernel.org/stable/c/c37a0461c0d0a70c5de4fdbd70449a7f53c12ddahttps://git.kernel.org/stable/c/db488d653d896fcf9ac87e15239924c2928bbc3c