
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-49032 is a vulnerability in the Linux kernel's AFE4404 driver that causes an out-of-bounds read in the afe4404_[read|write]_raw functions. The vulnerability was discovered in November 2022 and affects the Industrial I/O (IIO) health subsystem (Kernel Git).
The vulnerability occurs due to array size mismatch where afe4404_channel_leds and afe4404_channel_offdacs arrays are smaller than the number of channels, causing out-of-bounds read when accessed with chan->address. This was confirmed through KASAN (Kernel Address Sanitizer) which reported a global-out-of-bounds read in afe4404_read_raw+0x2ce/0x380 (Kernel Git).
When exploited, the vulnerability allows reading memory outside the intended buffer boundaries, which could potentially lead to information disclosure. The issue can be triggered through the sysfs interface by reading from /sys/bus/i2c/devices/0-0058/iio:device0/in_intensity6_raw (Kernel Git).
The issue has been fixed by moving the array access operations before their use in the code. The fix was implemented in commit fc92d9e3de0b2d30a3ccc08048a5fad533e4672b and backported to various stable kernel versions (Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."