PT-2022-6166 · Cisco+6 · Cisco+6

Published

2022-10-21

·

Updated

2023-11-29

·

CVE-2022-3643

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux (affected versions not specified)
Description The issue is related to the Linux network backend, specifically the netback driver, where a guest can trigger a NIC interface reset, abort, or crash by sending certain kinds of packets. This is due to an assumption in the Linux network stack that packet protocol headers are contained within the linear section of the SKB, which some NICs do not handle correctly if this assumption is not met. The problem has been reported with Cisco and Broadcom NetXtrem II BCM5780 NICs, but it may also affect other NICs or drivers. When the frontend sends requests with split headers, netback forwards these packets to the networking core, resulting in misbehavior.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Special Elements Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4282
ALT-PU-2023-4894
ALT-PU-2023-7007
BDU:2023-00265
CVE-2022-3643
DLA-3244-1
DLA-3245-1
LSN-0099-1
MGASA-2022-0477
MGASA-2022-0478
MGASA-2023-0008
OESA-2022-2144
OESA-2022-2147
OESA-2022-2162
OPENSUSE-SU-2022_4504-1
OPENSUSE-SU-2022_4574-1
OPENSUSE-SU-2022_4585-1
OPENSUSE-SU-2022_4617-1
OPENSUSE-SU-2023_0152-1
SUSE-SU-2022:4504-1
SUSE-SU-2022:4505-1
SUSE-SU-2022:4566-1
SUSE-SU-2022:4573-1
SUSE-SU-2022:4574-1
SUSE-SU-2022:4585-1
SUSE-SU-2022:4615-1
SUSE-SU-2022:4617-1
SUSE-SU-2023:0134-1
SUSE-SU-2023:0152-1
SUSE-SU-2023:0406-1
SUSE-SU-2023:0420-1
USN-5794-1
USN-5802-1
USN-5803-1
USN-5804-1
USN-5804-2
USN-5808-1
USN-5813-1
USN-5814-1
USN-5829-1
USN-5830-1
USN-5831-1
USN-5832-1
USN-5860-1
USN-5861-1
USN-5863-1
USN-5875-1
USN-5877-1
USN-5879-1
USN-5918-1

Affected Products

Alt Linux
Astra Linux
Broadcom Netxtrem Ii Bcm5780
Cisco
Linuxmint
Suse
Ubuntu