CVE-2022-48630: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commit referenced in the Fixes tag removed the 'break' from the else branch in qcom_rng_read(), causing an infinite loop whenever 'max' is not a multiple of WORD_SZ. This can be reproduced e.g. by running: kcapi-rng -b 67 >/dev/null There are many ways to fix this without adding back the 'break', but they all seem more awkward than simply adding it back, so do just that. Tested on a machine with Qualcomm Amberwing processor.
Affected products
- Linux Linux Kernel: from 4.19.236, before 4.19.245 (fixed in 4.19.245); from 5.4.187, before 5.4.196 (fixed in 5.4.196); from 5.10.108, before 5.10.118 (fixed in 5.10.118); from 5.15.31, before 5.15.42 (fixed in 5.15.42); from 5.17, before 5.17.10 (fixed in 5.17.10); version 5.18 only
Published 2024-03-05. Last modified 2026-06-17.