CVE-2022-48363
CVSS V2 None
CVSS V3 None
Description
In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer.
Overview
- CVE ID
- CVE-2022-48363
- Assigner
- cve@mitre.org
- Vulnerability Status
- Analyzed
- Published Version
- 2023-02-26T23:15:10
- Last Modified Date
- 2023-03-07T22:50:38
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:linuxfoundation:automotive_grade_linux:*:*:*:*:*:*:*:* | 1 | OR | 0.23.8 |
References
Reference URL | Reference Tags |
---|---|
https://gerrit.automotivelinux.org/gerrit/c/src/libqtappfw/+/28484 | Patch |
https://gerrit.automotivelinux.org/gerrit/c/src/libqtappfw/+/28485 | Patch |
https://gerrit.automotivelinux.org/gerrit/q/project:src%252Flibqtappfw+status:open | Not Applicable |
https://jira.automotivelinux.org/browse/SPEC-4661 | Exploit |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2022-48363 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48363 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 05:28:20 | Added to TrackCVE | |||
2023-04-17 05:28:24 | Weakness Enumeration | new |