CVE Database
/

CVE-2022-50394

Back to search

CVE-2022-50394

Published: Sep 18, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: i2c: ismt: Fix an out-of-bounds bug in ismt_access() When the driver does not check the data from the user, the variable 'data->block[0]' may be very large to cause an out-of-bounds bug. The following log can reveal it: [ 33.995542] i2c i2c-1: ioctl, cmd=0x720, arg=0x7ffcb3dc3a20 [ 33.995978] ismt_smbus 0000:00:05.0: I2C_SMBUS_BLOCK_DATA: WRITE [ 33.996475] ================================================================== [ 33.996995] BUG: KASAN: out-of-bounds in ismt_access.cold+0x374/0x214b [ 33.997473] Read of size 18446744073709551615 at addr ffff88810efcfdb1 by task ismt_poc/485 [ 33.999450] Call Trace: [ 34.001849] memcpy+0x20/0x60 [ 34.002077] ismt_access.cold+0x374/0x214b [ 34.003382] __i2c_smbus_xfer+0x44f/0xfb0 [ 34.004007] i2c_smbus_xfer+0x10a/0x390 [ 34.004291] i2cdev_ioctl_smbus+0x2c8/0x710 [ 34.005196] i2cdev_ioctl+0x5ec/0x74c Fix this bug by checking the size of 'data->block[0]' first.

VendorProductVersions

Linux

Linux

affected
13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 - < 4a7bb1d93addb2f67e36fed00a53cb7f270d7b7a
affected
13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 - < 03b7ef7a6c5ca1ff553470166b4919db88b810f6
affected
13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 - < bfe41d966c860a8ad4c735639d616da270c92735
affected
13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 - < cdcbae2c5003747ddfd14e29db9c1d5d7e7c44dd
affected
13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 - < 9ac541a0898e8ec187a3fa7024b9701cffae6bf2

+4 more versions

Linux

Linux

affected
3.9
unaffected
0 - < 3.9
unaffected
4.9.337 - <= 4.9.*
unaffected
4.14.303 - <= 4.14.*
unaffected
4.19.270 - <= 4.19.*

+6 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now