CVE-2022-50828 is a stack-out-of-bounds vulnerability in the Linux kernel's ZynqMP clock driver, specifically affecting the strncpy function. When a clock name exceeds 15 bytes, the Linux-ATF interface fails to null-terminate the string, leading to memory corruption. This issue primarily impacts systems utilizing Xilinx Zynq UltraScale+ MPSoC and Versal ACAP devices. The vulnerability has a low attack complexity as it can be triggered by providing an overly long clock name, potentially leading to system instability, denial of service, or information disclosure. While no CVSS score is provided, the KASAN report indicates a critical memory safety issue. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE. It is not listed on the CISA KEV catalog, suggesting it is not widely exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.2CNA affecteddefault affected | |
| Linux | Linux | >= 5852b1365df4414523210e444ac7df1dec09acb4, < 0a07b13af04d0db7325018aaa83b5ffe864790c9, >= 5852b1365df4414523210e444ac7df1dec09acb4, < 5dbfcf7b080306b65d9f756fadf46c9495793750, >= 5852b1365df4414523210e444ac7df1dec09acb4, < bce41e4ac6f5ca3b22a07e8cdadc12044bbf9d3b, >= 5852b1365df4414523210e444ac7df1dec09acb4, < d66fea97671fcb516bd6d34bcc033f650ac7ee91, >= 5852b1365df4414523210e444ac7df1dec09acb4, < d9e2585c3bcecb1c83febad31b9f450e93d2509e, >= 5852b1365df4414523210e444ac7df1dec09acb4, < dd80fb2dbf1cd8751efbe4e53e54056f56a9b115CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.