#VU71453 Buffer overflow in Linux kernel - CVE-2022-3077
Published: January 23, 2023
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the Linux kernel Intel’s iSMT SMBus host controller driver in the way it handles the I2C_SMBUS_BLOCK_PROC_CALL case. A local user can pass specially crafted data via the ioctl I2C_SMBUS call, trigger memory corruption and crash the kernel.