CVE-2022-48655: Debian Linux
High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Harden accesses to the reset domains Accessing reset domains descriptors by the index upon the SCMI drivers requests through the SCMI reset operations interface can potentially lead to out-of-bound violations if the SCMI driver misbehave. Add an internal consistency check before any such domains descriptors accesses.
Affected products
- Debian Debian Linux: version 10.0 only
- Linux Linux Kernel: from 5.4, before 5.4.277 (fixed in 5.4.277); from 5.5, before 5.10.218 (fixed in 5.10.218); from 5.11, before 5.15.71 (fixed in 5.15.71); after 5.16, before 5.19.12 (fixed in 5.19.12); version 6.0 only
Published 2024-04-28. Last modified 2026-06-17.