CVE-2022-50407

Source
https://cve.org/CVERecord?id=CVE-2022-50407
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50407.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-50407
Downstream
Published
2025-09-18T16:03:52.532Z
Modified
2026-04-02T08:28:28.875815Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
crypto: hisilicon/qm - increase the memory of local variables
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: hisilicon/qm - increase the memory of local variables

Increase the buffer to prevent stack overflow by fuzz test. The maximum length of the qos configuration buffer is 256 bytes. Currently, the value of the 'val buffer' is only 32 bytes. The sscanf does not check the dest memory length. So the 'val buffer' may stack overflow.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50407.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
263c9959c9376ec0217d6adc61222a53469eed3c
Fixed
34c4f8ad45b4ea814c7ecc3f23a2d292959d5a52
Fixed
fc521abb6ee4b8f06fdfc52646140dab6a2ed334
Fixed
3efe90af4c0c46c58dba1b306de142827153d9c0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50407.json"