An issue was discovered in the Linux kernel before 5.19. In pxa3xxgcuwrite in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of sizet versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third argument to copyfrom_user(), a heap overflow may occur. NOTE: the original discoverer disputes that the overflow can actually happen.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"339433132012151685286574295282781045626",
"67425550053042035046497453310607171304",
"138461461625815462342316540010372912860",
"300345079700812837357462302303905371029"
]
},
"source": "https://github.com/torvalds/linux/commit/a09d2d00af53b43c6f11e6ab3cb58443c2cac8a7",
"deprecated": false,
"id": "CVE-2022-39842-bacb7b59",
"signature_type": "Line",
"target": {
"file": "drivers/video/fbdev/pxa3xx-gcu.c"
},
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39842.json"