CVE-2022-48945
Linux Kernel vulnerability analysis and mitigation

Overview

In the Linux kernel, a vulnerability (CVE-2022-48945) was discovered in the media subsystem's vivid driver. The issue was found by syzkaller and involves a boundary check failure in the compose size handling. The vulnerability was reported when a page fault occurred at address ffffc9000a3b1000 during supervisor write access in kernel mode (Ubuntu).

Technical details

The vulnerability occurs because the code fails to check boundary conditions after adjusting compose->height in the V4L2_SEL_TGT_CROP case. This leads to a page fault with error code 0x0002 (not-present page) in the vivid driver. The issue manifests in the memcpy_erms function and affects the video capture functionality of the vivid test driver (Kernel Commit).

Impact

When triggered, this vulnerability results in a kernel page fault and system crash, potentially leading to denial of service conditions. The issue affects the kernel's media subsystem, specifically the vivid test driver used for video capture operations.

Mitigation and workarounds

The issue has been fixed by adding a v4l2_rect_map_inside() check to properly validate the compose boundary against the format rectangle. The fix has been implemented across multiple kernel versions, including Ubuntu's kernel packages for various releases (Ubuntu).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-fips
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-fips
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-oracle-6.8
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-nvidia-6.8
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • kernel-devel
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management