CVE-2022-3903

An incorrect read request flaw was found in the Infrared Transceiver USB driver in the Linux kernel. This issue occurs when a user attaches a malicious USB device. A local user could use this flaw to starve the resources, causing denial of service or potentially crashing the system.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:6.1:rc5:*:*:*:*:*:*

History

07 Nov 2023, 03:51

Type Values Removed Values Added
References
  • {'url': 'https://lore.kernel.org/all/CAB7eexLLApHJwZfMQ=X-PtRhw0BgO+5KcSMS05FNUYejJXqtSA@mail.gmail.com/', 'name': 'https://lore.kernel.org/all/CAB7eexLLApHJwZfMQ=X-PtRhw0BgO+5KcSMS05FNUYejJXqtSA@mail.gmail.com/', 'tags': ['Exploit', 'Mailing List', 'Vendor Advisory'], 'refsource': 'MISC'}
  • {'url': 'https://lore.kernel.org/all/E1obysd-009Grw-He@www.linuxtv.org/', 'name': 'https://lore.kernel.org/all/E1obysd-009Grw-He@www.linuxtv.org/', 'tags': ['Mailing List', 'Patch', 'Vendor Advisory'], 'refsource': 'MISC'}
  • () https://lore.kernel.org/all/E1obysd-009Grw-He%40www.linuxtv.org/ -
  • () https://lore.kernel.org/all/CAB7eexLLApHJwZfMQ=X-PtRhw0BgO+5KcSMS05FNUYejJXqtSA%40mail.gmail.com/ -

17 Nov 2022, 20:23

Type Values Removed Values Added
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
References (MISC) https://lore.kernel.org/all/CAB7eexLLApHJwZfMQ=X-PtRhw0BgO+5KcSMS05FNUYejJXqtSA@mail.gmail.com/ - (MISC) https://lore.kernel.org/all/CAB7eexLLApHJwZfMQ=X-PtRhw0BgO+5KcSMS05FNUYejJXqtSA@mail.gmail.com/ - Exploit, Mailing List, Vendor Advisory
References (MISC) https://lore.kernel.org/all/E1obysd-009Grw-He@www.linuxtv.org/ - (MISC) https://lore.kernel.org/all/E1obysd-009Grw-He@www.linuxtv.org/ - Mailing List, Patch, Vendor Advisory
CPE cpe:2.3:o:linux:linux_kernel:6.1:rc5:*:*:*:*:*:*

14 Nov 2022, 22:51

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-14 21:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-3903

Mitre link : CVE-2022-3903

CVE.ORG link : CVE-2022-3903


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')