SB20251230197 - Out-of-bounds read in Linux kernel hisilicon zip driver
Published: December 30, 2025 Updated: December 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2022-50814)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the sgl_sge_nr_set() function in drivers/crypto/hisilicon/zip/zip_crypto.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/272093471305261c4e07a2fc97c2d1e53cd56819
- https://git.kernel.org/stable/c/5eaebd19fbb0e26e73a34f55d3b1dc310df0eb15
- https://git.kernel.org/stable/c/d74f9340097a881869c4c22ca376654cc2516ecc
- https://git.kernel.org/stable/c/d88b88514ef28515ccfa1f1787c2aedef75a79dd
- https://git.kernel.org/stable/c/f8a983d6e01b198320d310cb1326364d7d973b2a
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.17