{"dataType":"CVE_RECORD","cveMetadata":{"cveId":"CVE-2022-48655","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-02-25T13:44:28.317Z","datePublished":"2024-04-28T13:01:00.822Z","dateUpdated":"2026-05-11T18:44:34.669Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-05-11T18:44:34.669Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Harden accesses to the reset domains\n\nAccessing reset domains descriptors by the index upon the SCMI drivers\nrequests through the SCMI reset operations interface can potentially\nlead to out-of-bound violations if the SCMI driver misbehave.\n\nAdd an internal consistency check before any such domains descriptors\naccesses."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/firmware/arm_scmi/reset.c"],"versions":[{"version":"95a15d80aa0de938299acfcbc6aa6f2b16f5d7e5","lessThan":"7184491fc515f391afba23d0e9b690caaea72daf","status":"affected","versionType":"git"},{"version":"95a15d80aa0de938299acfcbc6aa6f2b16f5d7e5","lessThan":"f2277d9e2a0d092c13bae7ee82d75432bb8b5108","status":"affected","versionType":"git"},{"version":"95a15d80aa0de938299acfcbc6aa6f2b16f5d7e5","lessThan":"1f08a1b26cfc53b7715abc46857c6023bb1b87de","status":"affected","versionType":"git"},{"version":"95a15d80aa0de938299acfcbc6aa6f2b16f5d7e5","lessThan":"8e65edf0d37698f7a6cb174608d3ec7976baf49e","status":"affected","versionType":"git"},{"version":"95a15d80aa0de938299acfcbc6aa6f2b16f5d7e5","lessThan":"e9076ffbcaed5da6c182b144ef9f6e24554af268","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/firmware/arm_scmi/reset.c"],"versions":[{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","status":"unaffected","versionType":"semver"},{"version":"5.4.277","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.218","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.71","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"5.19.12","lessThanOrEqual":"5.19.*","status":"unaffected","versionType":"semver"},{"version":"6.0","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"5.4.277"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"5.10.218"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"5.15.71"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"5.19.12"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.0"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7184491fc515f391afba23d0e9b690caaea72daf"},{"url":"https://git.kernel.org/stable/c/f2277d9e2a0d092c13bae7ee82d75432bb8b5108"},{"url":"https://git.kernel.org/stable/c/1f08a1b26cfc53b7715abc46857c6023bb1b87de"},{"url":"https://git.kernel.org/stable/c/8e65edf0d37698f7a6cb174608d3ec7976baf49e"},{"url":"https://git.kernel.org/stable/c/e9076ffbcaed5da6c182b144ef9f6e24554af268"}],"title":"firmware: arm_scmi: Harden accesses to the reset domains","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-125","lang":"en","description":"CWE-125 Out-of-bounds Read"}]}],"affected":[{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:a:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"version":"95a15d80aa0d","status":"affected","lessThan":"7184491fc515","versionType":"custom"},{"version":"95a15d80aa0d","status":"affected","lessThan":"f2277d9e2a0d","versionType":"custom"},{"version":"95a15d80aa0d","status":"affected","lessThan":"1f08a1b26cfc","versionType":"custom"},{"version":"95a15d80aa0d","status":"affected","lessThan":"8e65edf0d376","versionType":"custom"},{"version":"95a15d80aa0d","status":"affected","lessThan":"e9076ffbcaed","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:5.4:*:*:*:*:*:*:*"],"defaultStatus":"affected","versions":[{"version":"5.4","status":"affected"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":8.1,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"HIGH","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-06-05T04:01:14.973732Z","id":"CVE-2022-48655","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-05T13:55:57.618Z"}},{"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/7184491fc515f391afba23d0e9b690caaea72daf","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/f2277d9e2a0d092c13bae7ee82d75432bb8b5108","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/1f08a1b26cfc53b7715abc46857c6023bb1b87de","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/8e65edf0d37698f7a6cb174608d3ec7976baf49e","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/e9076ffbcaed5da6c182b144ef9f6e24554af268","tags":["x_transferred"]},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html","tags":["x_transferred"]},{"url":"https://security.netapp.com/advisory/ntap-20240912-0008/"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-09-12T16:02:54.021Z"}}]},"dataVersion":"5.2"}