Lucene search

K
vulnrichmentLinuxVULNRICHMENT:CVE-2022-48743
HistoryJun 20, 2024 - 11:13 a.m.

CVE-2022-48743 net: amd-xgbe: Fix skb data length underflow

2024-06-2011:13:27
Linux
github.com
7
vulnerability resolved
intermittent kernel panic
hardware descriptors

AI Score

6.8

Confidence

Low

EPSS

0

Percentile

5.0%

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

In the Linux kernel, the following vulnerability has been resolved:

net: amd-xgbe: Fix skb data length underflow

There will be BUG_ON() triggered in include/linux/skbuff.h leading to
intermittent kernel panic, when the skb length underflow is detected.

Fix this by dropping the packet if such length underflows are seen
because of inconsistencies in the hardware descriptors.

CNA Affected

[
  {
    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
    "vendor": "Linux",
    "product": "Linux",
    "versions": [
      {
        "status": "affected",
        "version": "fafc9555d87a",
        "lessThan": "9924c80bd484",
        "versionType": "git"
      },
      {
        "status": "affected",
        "version": "622c36f143fc",
        "lessThan": "617f9934bb37",
        "versionType": "git"
      },
      {
        "status": "affected",
        "version": "622c36f143fc",
        "lessThan": "34aeb4da20f9",
        "versionType": "git"
      },
      {
        "status": "affected",
        "version": "622c36f143fc",
        "lessThan": "9892742f035f",
        "versionType": "git"
      },
      {
        "status": "affected",
        "version": "622c36f143fc",
        "lessThan": "4d3fcfe84648",
        "versionType": "git"
      },
      {
        "status": "affected",
        "version": "622c36f143fc",
        "lessThan": "db6fd92316a2",
        "versionType": "git"
      },
      {
        "status": "affected",
        "version": "622c36f143fc",
        "lessThan": "e8f73f620fee",
        "versionType": "git"
      },
      {
        "status": "affected",
        "version": "622c36f143fc",
        "lessThan": "5aac9108a180",
        "versionType": "git"
      }
    ],
    "programFiles": [
      "drivers/net/ethernet/amd/xgbe/xgbe-drv.c"
    ],
    "defaultStatus": "unaffected"
  },
  {
    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
    "vendor": "Linux",
    "product": "Linux",
    "versions": [
      {
        "status": "affected",
        "version": "4.11"
      },
      {
        "status": "unaffected",
        "version": "0",
        "lessThan": "4.11",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "4.9.300",
        "versionType": "custom",
        "lessThanOrEqual": "4.9.*"
      },
      {
        "status": "unaffected",
        "version": "4.14.265",
        "versionType": "custom",
        "lessThanOrEqual": "4.14.*"
      },
      {
        "status": "unaffected",
        "version": "4.19.228",
        "versionType": "custom",
        "lessThanOrEqual": "4.19.*"
      },
      {
        "status": "unaffected",
        "version": "5.4.177",
        "versionType": "custom",
        "lessThanOrEqual": "5.4.*"
      },
      {
        "status": "unaffected",
        "version": "5.10.97",
        "versionType": "custom",
        "lessThanOrEqual": "5.10.*"
      },
      {
        "status": "unaffected",
        "version": "5.15.20",
        "versionType": "custom",
        "lessThanOrEqual": "5.15.*"
      },
      {
        "status": "unaffected",
        "version": "5.16.6",
        "versionType": "custom",
        "lessThanOrEqual": "5.16.*"
      },
      {
        "status": "unaffected",
        "version": "5.17",
        "versionType": "original_commit_for_fix",
        "lessThanOrEqual": "*"
      }
    ],
    "programFiles": [
      "drivers/net/ethernet/amd/xgbe/xgbe-drv.c"
    ],
    "defaultStatus": "affected"
  }
]

AI Score

6.8

Confidence

Low

EPSS

0

Percentile

5.0%

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial