CVE-2022-49163: Linux Kernel

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: fix a bug of accessing array out of bounds When error occurs in parsing jpeg, the slot isn't acquired yet, it may be the default value MXC_MAX_SLOTS. If the driver access the slot using the incorrect slot number, it will access array out of bounds. The result is the driver will change num_domains, which follows slot_data in struct mxc_jpeg_dev. Then the driver won't detach the pm domain at rmmod, which will lead to kernel panic when trying to insmod again.

Affected products

  • Linux Linux Kernel: from 5.13, before 5.15.33 (fixed in 5.15.33); from 5.16, before 5.16.19 (fixed in 5.16.19); from 5.17, before 5.17.2 (fixed in 5.17.2)

Published 2025-02-26. Last modified 2026-08-04.