CVE-2022-27223
High
CVE-2022-27223
In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.
Exploit probability
2.2%
Published
March 16, 2022
Required by
Not available
Last source change
April 11, 2026
02 / AFFECTED SOFTWARE
Affected packages
714 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2022-27223
View original source
In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.
05 / REFERENCES