PT-2022-7491 · Linux+2 · Linux Kernel+2
Yevgeny Kliteynik
·
Published
2022-02-23
·
Updated
2024-09-27
·
CVE-2022-48932
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to a slab-out-of-bounds problem in the
mlx5 cmd dr create fte function when adding a rule with 32 destinations. This can cause an out-of-band access issue, leading to a potential denial of service. The problem is fixed by increasing the allocated buffers and checking the number of actions to prevent the issue.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Red Os
Suse