
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-48655 is a vulnerability in the Linux kernel's ARM SCMI (System Control and Management Interface) message protocol, discovered and disclosed in April 2024. The vulnerability affects various versions of the Linux kernel from 5.4 through 6.0-rc6, including multiple distribution versions such as Ubuntu and Debian. This vulnerability is related to how the kernel handles reset domains descriptors in the SCMI drivers (NVD).
The vulnerability occurs when accessing reset domains descriptors by index upon SCMI drivers requests through the SCMI reset operations interface. This can potentially lead to out-of-bounds violations if the SCMI driver misbehaves. The issue has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating local access requirements but high potential impact (NVD, NetApp Advisory).
Successful exploitation of this vulnerability could lead to disclosure of information, addition or modification of data, or Denial of Service (DoS). The vulnerability affects multiple versions of the Linux kernel and has been classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-125 (Out-of-bounds Read) (NetApp Advisory).
The vulnerability requires local access with low complexity and low privileges to exploit. No user interaction is required for exploitation. While public discussion of this vulnerability exists, there are no known reports of active exploitation in the wild (NetApp Advisory).
The vulnerability has been fixed through an internal consistency check implementation before any domains descriptors accesses. Multiple Linux distributions have released patches, including Ubuntu (versions 22.04 LTS, 20.04 LTS) and Debian (version 10 buster). The fix involves updating to patched kernel versions: Ubuntu 22.04 LTS (5.15.0-57.63), Ubuntu 20.04 LTS (5.4.0-190.210), and Debian 10 (5.10.218-1~deb10u1) (Ubuntu Security, Debian LTS).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."