← Back to CVE List
Vulnerability Intelligence Report

CVE-2022-27223

In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
EPSS Probability:2.08%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
linux linux_kernel all
netapp active_iq_unified_manager all
netapp h500s_firmware all
netapp h500s all
netapp h700s_firmware all
netapp h700s all
netapp h300e_firmware all
netapp h300e all
netapp h500e_firmware all
netapp h500e all
netapp h700e_firmware all
netapp h700e all
netapp h410s_firmware all
netapp h410s all
netapp h300s_firmware all
netapp h300s all
debian debian_linux 9.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.083%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2022-03-15T00:00:00
Published2022-03-15T23:51:07
Last Updated2024-08-03T05:25:32

LINK COPIED TO CLIPBOARD