CVE-2022-2652
Estado: ModificadaMedia (6)—
Depending on the way the format strings in the card label are crafted it's possible to leak kernel stack memory. There is also the possibility for DoS due to the v4l2loopback kernel module crashing when providing the card label on request (reproduce e.g. with many %s modifiers in a row).
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
- Puntuación base: 6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 25
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-134
Referencias
- https://github.com/umlaeute/v4l2loopback/commit/e4cd225557486c420f6a34411f98c575effd43dd
- https://huntr.dev/bounties/1b055da5-7a9e-4409-99d7-030280d242d5
- https://github.com/umlaeute/v4l2loopback/commit/e4cd225557486c420f6a34411f98c575effd43dd
- https://huntr.dev/bounties/1b055da5-7a9e-4409-99d7-030280d242d5
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-2652",
"cveTags": [],
"metrics": {
"cvssMetricV30": [
{
"type": "Secondary",
"source": "security@huntr.dev",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 7.3,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.3,
"exploitabilityScore": 1.5
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "security@huntr.dev",
"affectedData": [
{
"vendor": "umlaeute",
"product": "umlaeute/v4l2loopback",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "0.12.6",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-08-04T10:15:07.990",
"references": [
{
"url": "https://github.com/umlaeute/v4l2loopback/commit/e4cd225557486c420f6a34411f98c575effd43dd",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security@huntr.dev"
},
{
"url": "https://huntr.dev/bounties/1b055da5-7a9e-4409-99d7-030280d242d5",
"tags": [
"Exploit",
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"source": "security@huntr.dev"
},
{
"url": "https://github.com/umlaeute/v4l2loopback/commit/e4cd225557486c420f6a34411f98c575effd43dd",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://huntr.dev/bounties/1b055da5-7a9e-4409-99d7-030280d242d5",
"tags": [
"Exploit",
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@huntr.dev",
"description": [
{
"lang": "en",
"value": "CWE-134"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Depending on the way the format strings in the card label are crafted it's possible to leak kernel stack memory. There is also the possibility for DoS due to the v4l2loopback kernel module crashing when providing the card label on request (reproduce e.g. with many %s modifiers in a row)."
},
{
"lang": "es",
"value": "Dependiendo de la forma en que sean diseñadas las cadenas de formato en la etiqueta de la tarjeta, es posible filtrar la memoria de la pila del kernel. También se presenta la posibilidad de DoS debido a que el módulo del kernel v4l2loopback es bloqueado cuando es proporcionada la etiqueta de la tarjeta a petición (es reproducido, por ejemplo, con muchos modificadores %s en una fila)"
}
],
"lastModified": "2026-06-17T04:42:17.237",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:v4l2loopback_project:v4l2loopback:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80644B02-6794-437D-8E55-1F0BD2763E67",
"versionEndExcluding": "0.12.6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@huntr.dev"
}