PT-2022-7507 · Linux+3 · Linux Kernel+3

Dan Carpenter

·

Published

2022-03-15

·

Updated

2024-08-30

·

CVE-2022-48841

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a NULL pointer dereference in the ice update vsi tx ring stats() function, which updates Tx ring stats. This can lead to a denial of service. The problem occurs because the function accesses the ring to propagate gathered Tx stats onto VSI stats, even when the ring pointer is NULL. The existing logic has been changed to move to the next ring when the ring is NULL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-43351
BDU:2024-06684
CVE-2022-48841
OPENSUSE-SU-2024_2947-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2902-1
SUSE-SU-2024:2929-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2947-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse