{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2022-50097",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-06-18T10:57:27.411Z",
        "datePublished": "2025-06-18T11:02:34.589Z",
        "dateUpdated": "2026-08-05T08:57:23.864Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T08:57:23.864Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvideo: fbdev: s3fb: Check the size of screen before memset_io()\n\nIn the function s3fb_set_par(), the value of 'screen_size' is\ncalculated by the user input. If the user provides the improper value,\nthe value of 'screen_size' may larger than 'info->screen_size', which\nmay cause the following bug:\n\n[   54.083733] BUG: unable to handle page fault for address: ffffc90003000000\n[   54.083742] #PF: supervisor write access in kernel mode\n[   54.083744] #PF: error_code(0x0002) - not-present page\n[   54.083760] RIP: 0010:memset_orig+0x33/0xb0\n[   54.083782] Call Trace:\n[   54.083788]  s3fb_set_par+0x1ec6/0x4040\n[   54.083806]  fb_set_var+0x604/0xeb0\n[   54.083836]  do_fb_ioctl+0x234/0x670\n\nFix the this by checking the value of 'screen_size' before memset_io()."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The bug is triggered through the local fbdev ioctl path (open /dev/fbN, FBIOPUT_VSCREENINFO → do_fb_ioctl → fb_set_var → s3fb_set_par), not via network or adjacent protocols.\nAC:L - An attacker who can issue FBIOPUT_VSCREENINFO reliably controls xres_virtual/yres_virtual/bits_per_pixel to bypass s3fb_check_var (signed int mem overflow or bpp==0 text mode) and force an oversized memset_io; no race or external conditions are required.\nPR:L - There is no CAP_SYS_ADMIN check on FBIOPUT_VSCREENINFO; access is only gated by /dev/fbN DAC permissions (typically root:video 0660), so an unprivileged video-group user can reach the vulnerable code.\nUI:N - Exploitation requires only the attacker's own open/ioctl against the framebuffer device; no separate victim action is needed.\nS:U - This is a standard in-kernel driver memory-safety bug affecting the host kernel/device; it does not cross a VM, IOMMU, or other security authority boundary.\nC:N - The corruption is a memset_io of fixed zeros into the PCI framebuffer aperture (and past it into unmapped ioremap space); there is no out-of-bounds read or other information-disclosure primitive.\nI:H - User-controlled dimensions cause an out-of-bounds write via memset_io beyond info->screen_size into the mapped BAR (and beyond), which is kernel-mediated memory corruption of framebuffer/MMIO space.\nA:H - The demonstrated result is a kernel page-fault oops in memset when the write runs past the ioremap'd region, which can panic or otherwise take down the system."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/video/fbdev/s3fb.c"
                    ],
                    "versions": [
                        {
                            "version": "a268422de8bf1b4c0cb97987b6c329c9f6a3da4b",
                            "lessThan": "574912261528589012b61f82d368256247c3a5a8",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a268422de8bf1b4c0cb97987b6c329c9f6a3da4b",
                            "lessThan": "3c35a0dc2b4e7acf24c796043b64fa3eee799239",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a268422de8bf1b4c0cb97987b6c329c9f6a3da4b",
                            "lessThan": "eacb50f1733660911827d7c3720f4c5425d0cdda",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a268422de8bf1b4c0cb97987b6c329c9f6a3da4b",
                            "lessThan": "5e0da18956d38e7106664dc1d06367b22f06edd3",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a268422de8bf1b4c0cb97987b6c329c9f6a3da4b",
                            "lessThan": "ce50d94afcb8690813c5522f24cd38737657db81",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a268422de8bf1b4c0cb97987b6c329c9f6a3da4b",
                            "lessThan": "52461d387cc8c8f8dc40320caa2e9e101f73e7ba",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a268422de8bf1b4c0cb97987b6c329c9f6a3da4b",
                            "lessThan": "e2d7cacc6a2a1d77e7e20a492daf458a12cf19e0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a268422de8bf1b4c0cb97987b6c329c9f6a3da4b",
                            "lessThan": "6ba592fa014f21f35a8ee8da4ca7b95a018f13e8",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/video/fbdev/s3fb.c"
                    ],
                    "versions": [
                        {
                            "version": "2.6.21",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "2.6.21",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "4.14.291",
                            "lessThanOrEqual": "4.14.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "4.19.256",
                            "lessThanOrEqual": "4.19.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.4.211",
                            "lessThanOrEqual": "5.4.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.137",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.61",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.18.18",
                            "lessThanOrEqual": "5.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.19.2",
                            "lessThanOrEqual": "5.19.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.0",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.21",
                                    "versionEndExcluding": "4.14.291"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.21",
                                    "versionEndExcluding": "4.19.256"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.21",
                                    "versionEndExcluding": "5.4.211"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.21",
                                    "versionEndExcluding": "5.10.137"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.21",
                                    "versionEndExcluding": "5.15.61"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.21",
                                    "versionEndExcluding": "5.18.18"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.21",
                                    "versionEndExcluding": "5.19.2"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.21",
                                    "versionEndExcluding": "6.0"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/574912261528589012b61f82d368256247c3a5a8"
                },
                {
                    "url": "https://git.kernel.org/stable/c/3c35a0dc2b4e7acf24c796043b64fa3eee799239"
                },
                {
                    "url": "https://git.kernel.org/stable/c/eacb50f1733660911827d7c3720f4c5425d0cdda"
                },
                {
                    "url": "https://git.kernel.org/stable/c/5e0da18956d38e7106664dc1d06367b22f06edd3"
                },
                {
                    "url": "https://git.kernel.org/stable/c/ce50d94afcb8690813c5522f24cd38737657db81"
                },
                {
                    "url": "https://git.kernel.org/stable/c/52461d387cc8c8f8dc40320caa2e9e101f73e7ba"
                },
                {
                    "url": "https://git.kernel.org/stable/c/e2d7cacc6a2a1d77e7e20a492daf458a12cf19e0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/6ba592fa014f21f35a8ee8da4ca7b95a018f13e8"
                }
            ],
            "title": "video: fbdev: s3fb: Check the size of screen before memset_io()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}