Review reviewHigh

CVE-2022-50394

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: i2c: ismt: Fix an out-of-bounds bug in ismt_access() When the driver does not check the data from the user, the variable 'data->block[0]' may be very large to cause an out-of-bounds bug. The following log can reveal it: [ 33.995542] i2c i2c-1: ioctl, cmd=0x720, arg=0x7ffcb3dc3a20 [ 33.995978] ismt_smbus 0000:00:05.0: I2C_SMBUS_BLOCK_DATA: WRITE [ 33.996475] ================================================================== [ 33.996995] BUG: KASAN: out-of-bounds in ismt_access.cold+0x374/0x214b [ 33.997473] Read of size 1844...

CVSS
7.1
EPSS
0.16%
5.27% percentile
CISA KEV
Not listed
Published
2025.09.18
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.16%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: i2c: ismt: Fix an out-of-bounds bug in ismt_access() When the driver does not check the data from the user, the variable 'data->block[0]' may be very large to cause an out-of-bounds bug. The following log can reveal it: [ 33.995542] i2c i2c-1: ioctl, cmd=0x720, arg=0x7ffcb3dc3a20 [ 33.995978] ismt_smbus 0000:00:05.0: I2C_SMBUS_BLOCK_DATA: WRITE [ 33.996475] ================================================================== [ 33.996995] BUG: KASAN: out-of-bounds in ismt_access.cold+0x374/0x214b [ 33.997473] Read of size 1844...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 < 4a7bb1d93addb2f67e36fed00a53cb7f270d7b7a, >= 13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 < 03b7ef7a6c5ca1ff553470166b4919db88b810f6, >= 13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 < bfe41d966c860a8ad4c735639d616da270c92735, >= 13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 < cdcbae2c5003747ddfd14e29db9c1d5d7e7c44dd, >= 13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 < 9ac541a0898e8ec187a3fa7024b9701cffae6bf2, >= 13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 < 96c12fd0ec74641295e1c3c34dea3dce1b6c3422, >= 13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 < a642469d464b2780a25a49b51ae56623c65eac34, >= 13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 < 233348a04becf133283f0076e20b317302de21d9, >= 13f35ac14cd0a9a1c4f0034c4c40d0ae98844ce9 < 39244cc754829bf707dccd12e2ce37510f5b1f8d, >= 3.9, >= 3.9 < 4.9.337, >= 4.10 < 4.14.303, >= 4.15 < 4.19.270, >= 4.20 < 5.4.229, >= 5.5 < 5.10.163, >= 5.11 < 5.15.86, >= 5.16 < 6.0.16, >= 6.1 < 6.1.2
Fixed versions
4.9.337, 4.14.303, 4.19.270, 5.4.229, 5.10.163, 5.15.86, 6.0.16, 6.1.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125
CVE-2022-50394 — Linux Linux, linux kernel | SECUFOCUS NOW