CVE-2022-48672: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: of: fdt: fix off-by-one error in unflatten_dt_nodes() Commit 78c44d910d3e ("drivers/of: Fix depth when unflattening devicetree") forgot to fix up the depth check in the loop body in unflatten_dt_nodes() which makes it possible to overflow the nps[] buffer... Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.

Affected products

  • Linux Linux Kernel: from 4.7, before 4.14.295 (fixed in 4.14.295); from 4.15, before 4.19.260 (fixed in 4.19.260); from 4.20, before 5.4.215 (fixed in 5.4.215); from 5.5, before 5.10.145 (fixed in 5.10.145); from 5.11, before 5.15.70 (fixed in 5.15.70); from 5.16, before 5.19.11 (fixed in 5.19.11)

Published 2024-05-03. Last modified 2026-06-17.