PT-2024-10521 · Linux+3 · Linux Kernel+3

Dave Ertman

·

Published

2022-02-10

·

Updated

2025-01-20

·

CVE-2022-48807

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to errors in reading beyond the allocated buffer memory in the ice component of the Linux kernel. This can cause a denial of service. The problem occurs because the same handler is called for both a NETDEV BONDING INFO LAG unlink notification and a NETDEV UNREGISTER call, resulting in a KASAN stack-out-of-bounds error due to the different structure of the netdev notifier info passed depending on the event.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01072
CVE-2022-48807
OPENSUSE-SU-2024_2947-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2902-1
SUSE-SU-2024:2929-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2947-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse