PT-2022-7498 · Linux+5 · Linux Kernel+5

Oliver Neukum

·

Published

2022-02-15

·

Updated

2025-01-14

·

CVE-2022-48938

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the CDC-NCM component in the Linux kernel, where a broken device may provide an extreme offset and a reasonable length for a fragment, causing an integer overflow in the sanity check. This defeats the sanity check, allowing potential exploitation. The quantities offset and offset + len should be checked to prevent overflow, and these quantities should be unsigned.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06655
CVE-2022-48938
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3408-1
OPENSUSE-SU-2024_3483-1
SUSE-SU-2024:3189-1
SUSE-SU-2024:3190-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3227-1
SUSE-SU-2024:3251-1
SUSE-SU-2024:3252-1
SUSE-SU-2024:3408-1
SUSE-SU-2024:3483-1
USN-7121-1
USN-7121-2
USN-7121-3
USN-7148-1
USN-7159-1
USN-7159-2
USN-7159-3
USN-7159-4
USN-7159-5
USN-7195-1
USN-7195-2

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu