{"id":"DEBIAN-CVE-2022-48847","details":"In the Linux kernel, the following vulnerability has been resolved:  watch_queue: Fix filter limit check  In watch_queue_set_filter(), there are a couple of places where we check that the filter type value does not exceed what the type_filter bitmap can hold.  One place calculates the number of bits by:     if (tf[i].type \u003e= sizeof(wfilter-\u003etype_filter) * 8)  which is fine, but the second does:     if (tf[i].type \u003e= sizeof(wfilter-\u003etype_filter) * BITS_PER_LONG)  which is not.  This can lead to a couple of out-of-bounds writes due to a too-large type:   (1) __set_bit() on wfilter-\u003etype_filter  (2) Writing more elements in wfilter-\u003efilters[] than we allocated.  Fix this by just using the proper WATCH_TYPE__NR instead, which is the number of types we actually know about.  The bug may cause an oops looking something like:    BUG: KASAN: slab-out-of-bounds in watch_queue_set_filter+0x659/0x740   Write of size 4 at addr ffff88800d2c66bc by task watch_queue_oob/611   ...   Call Trace:    \u003cTASK\u003e    dump_stack_lvl+0x45/0x59    print_address_description.constprop.0+0x1f/0x150    ...    kasan_report.cold+0x7f/0x11b    ...    watch_queue_set_filter+0x659/0x740    ...    __x64_sys_ioctl+0x127/0x190    do_syscall_64+0x43/0x90    entry_SYSCALL_64_after_hwframe+0x44/0xae    Allocated by task 611:    kasan_save_stack+0x1e/0x40    __kasan_kmalloc+0x81/0xa0    watch_queue_set_filter+0x23a/0x740    __x64_sys_ioctl+0x127/0x190    do_syscall_64+0x43/0x90    entry_SYSCALL_64_after_hwframe+0x44/0xae    The buggy address belongs to the object at ffff88800d2c66a0    which belongs to the cache kmalloc-32 of size 32   The buggy address is located 28 bytes inside of    32-byte region [ffff88800d2c66a0, ffff88800d2c66c0)","modified":"2026-09-01T16:05:29.117341465Z","published":"2024-07-16T13:15:11.950Z","upstream":["CVE-2022-48847"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-48847"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.18-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48847.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.18-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48847.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.18-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48847.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}