CVE Database
/

CVE-2022-48836

Back to search

CVE-2022-48836

Published: Jul 16, 2024

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: Input: aiptek - properly check endpoint type Syzbot reported warning in usb_submit_urb() which is caused by wrong endpoint type. There was a check for the number of endpoints, but not for the type of endpoint. Fix it by replacing old desc.bNumEndpoints check with usb_find_common_endpoints() helper for finding endpoints Fail log: usb 5-1: BOGUS urb xfer, pipe 1 != type 3 WARNING: CPU: 2 PID: 48 at drivers/usb/core/urb.c:502 usb_submit_urb+0xed2/0x18a0 drivers/usb/core/urb.c:502 Modules linked in: CPU: 2 PID: 48 Comm: kworker/2:2 Not tainted 5.17.0-rc6-syzkaller-00226-g07ebd38a0da2 #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014 Workqueue: usb_hub_wq hub_event ... Call Trace: <TASK> aiptek_open+0xd5/0x130 drivers/input/tablet/aiptek.c:830 input_open_device+0x1bb/0x320 drivers/input/input.c:629 kbd_connect+0xfe/0x160 drivers/tty/vt/keyboard.c:1593

VendorProductVersions

Linux

Linux

affected
8e20cf2bce122ce9262d6034ee5d5b76fbb92f96 - < 57277a8b5d881e02051ba9d7f6cb3f915c229821
affected
8e20cf2bce122ce9262d6034ee5d5b76fbb92f96 - < fc8033a55e2796d21e370260a784ac9fbb8305a6
affected
8e20cf2bce122ce9262d6034ee5d5b76fbb92f96 - < 6de20111cd0bb7da9b2294073ba00c7d2a6c1c4f
affected
8e20cf2bce122ce9262d6034ee5d5b76fbb92f96 - < e732b0412f8c603d1e998f3bff41b5e7d5c3914c
affected
8e20cf2bce122ce9262d6034ee5d5b76fbb92f96 - < f0d43d22d24182b94d7eb78a2bf6ae7e2b33204a

+7 more versions

Linux

Linux

affected
4.4
unaffected
0 - < 4.4
unaffected
4.9.308 - <= 4.9.*
unaffected
4.14.273 - <= 4.14.*
unaffected
4.19.236 - <= 4.19.*

+5 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now