{"id":"DEBIAN-CVE-2022-48871","details":"In the Linux kernel, the following vulnerability has been resolved:  tty: serial: qcom-geni-serial: fix slab-out-of-bounds on RX FIFO buffer  Driver's probe allocates memory for RX FIFO (port-\u003erx_fifo) based on default RX FIFO depth, e.g. 16.  Later during serial startup the qcom_geni_serial_port_setup() updates the RX FIFO depth (port-\u003erx_fifo_depth) to match real device capabilities, e.g. to 32.  The RX UART handle code will read \"port-\u003erx_fifo_depth\" number of words into \"port-\u003erx_fifo\" buffer, thus exceeding the bounds.  This can be observed in certain configurations with Qualcomm Bluetooth HCI UART device and KASAN:    Bluetooth: hci0: QCA Product ID   :0x00000010   Bluetooth: hci0: QCA SOC Version  :0x400a0200   Bluetooth: hci0: QCA ROM Version  :0x00000200   Bluetooth: hci0: QCA Patch Version:0x00000d2b   Bluetooth: hci0: QCA controller version 0x02000200   Bluetooth: hci0: QCA Downloading qca/htbtfw20.tlv   bluetooth hci0: Direct firmware load for qca/htbtfw20.tlv failed with error -2   Bluetooth: hci0: QCA Failed to request file: qca/htbtfw20.tlv (-2)   Bluetooth: hci0: QCA Failed to download patch (-2)   ==================================================================   BUG: KASAN: slab-out-of-bounds in handle_rx_uart+0xa8/0x18c   Write of size 4 at addr ffff279347d578c0 by task swapper/0/0    CPU: 0 PID: 0 Comm: swapper/0 Not tainted 6.1.0-rt5-00350-gb2450b7e00be-dirty #26   Hardware name: Qualcomm Technologies, Inc. Robotics RB5 (DT)   Call trace:    dump_backtrace.part.0+0xe0/0xf0    show_stack+0x18/0x40    dump_stack_lvl+0x8c/0xb8    print_report+0x188/0x488    kasan_report+0xb4/0x100    __asan_store4+0x80/0xa4    handle_rx_uart+0xa8/0x18c    qcom_geni_serial_handle_rx+0x84/0x9c    qcom_geni_serial_isr+0x24c/0x760    __handle_irq_event_percpu+0x108/0x500    handle_irq_event+0x6c/0x110    handle_fasteoi_irq+0x138/0x2cc    generic_handle_domain_irq+0x48/0x64  If the RX FIFO depth changes after probe, be sure to resize the buffer.","modified":"2026-09-01T16:05:29.381086638Z","published":"2024-08-21T07:15:04.207Z","upstream":["CVE-2022-48871"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-48871"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.8-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48871.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.8-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48871.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.8-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48871.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}]}