
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-49162 affects the Linux kernel's sm712fb framebuffer driver. The vulnerability was discovered when the driver writes three bytes to the framebuffer, causing a crash due to a page fault at address ffffc90001ffffff. The issue was identified in the smtcfb_write() function of the driver (Kernel Git).
The vulnerability occurs in the Linux kernel's video framebuffer driver (sm712fb). When writing three bytes to the framebuffer, the driver crashes with a page fault. The crash occurs in the smtcfbwrite() function with the following call trace: vfswrite+0x291/0xd60 -> dosysopenat2+0x27d/0x350 -> _fgetlight+0x54/0x340 -> ksyswrite+0xce/0x190 -> dosyscall64+0x43/0x90 -> entrySYSCALL64after_hwframe+0x44/0xae (Kernel Git).
The vulnerability results in a system crash when writing specific amounts of data to the framebuffer device, causing a denial of service condition for systems using the sm712fb driver (NVD).
The vulnerability has been fixed by removing the open-coded endianness fixup-code in the sm712fb driver. The fix was implemented through a patch that simplifies the buffer writing logic (Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."