Back to search
CVE-2022-48730
Published: Jun 20, 2024
Modified: May 11, 2026
PUBLISHED
Description
In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix potential spectre v1 gadget It appears like nr could be a Spectre v1 gadget as it's supplied by a user and used as an array index. Prevent the contents of kernel memory from being leaked to userspace via speculative execution by using array_index_nospec. [sumits: added fixes and cc: stable tags]
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected c02a81fba74fe3488ad6b08bfb5a1329005418f8 - < 5d40f1bdad3dd1a177f21a90ad4353c1ed40ba3aaffected c02a81fba74fe3488ad6b08bfb5a1329005418f8 - < 24f8e12d965b24f8aea762589e0e9fe2025c005eaffected c02a81fba74fe3488ad6b08bfb5a1329005418f8 - < cc8f7940d9c2d45f67b3d1a2f2b7a829ca561bedaffected c02a81fba74fe3488ad6b08bfb5a1329005418f8 - < 92c4cfaee6872038563c5b6f2e8e613f9d84d47d |
Linux | Linux | affected 5.6unaffected 0 - < 5.6unaffected 5.10.99 - <= 5.10.*unaffected 5.15.22 - <= 5.15.*unaffected 5.16.8 - <= 5.16.*+1 more versions |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now