yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-48554
Component Overview
Vulnerability Overview
Name
CVE-2022-48554
Source
NVD (
link
)
Debian (
link
)
Description
File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.
CWEs
CWE-125
Published Date
Aug 22, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugs.astron.com/view.php?id=310
Exploit
https://security.netapp.com/advisory/ntap-20231116-0002/
Third Party Advisory
https://www.debian.org/security/2023/dsa-5489
Third Party Advisory
https://bugs.astron.com/view.php?id=310
Exploit
https://security.netapp.com/advisory/ntap-20231116-0002/
Third Party Advisory
https://www.debian.org/security/2023/dsa-5489
Third Party Advisory
Analysis
#
Affected Component
Analysis
file
Patched
Vulnerability Rating
#
5.5
CVSSv31
Others affected components
#
Name
Project
Project Version
Version
Status
file
buildroot
2025.02.x
5.46
Not Affected
file
buildroot
master
5.47
Not Affected
file
openwrt
master
5.45-r1
Not Affected
file
openwrt
openwrt-25.12
5.45-r1
Not Affected
file
yocto
master
5.48
Not Affected
file
yocto
scarthgap
5.45
Not Affected
Resolved with patches
#
file (yocto:kirkstone)
#
Title
Author
Resolve
1
PR/310: p870613: Don't use strlcpy to copy the string, it
Christos Zoulas <christos@zoulas.com>
CVE-2022-48554