CVE-2022-2964Improper Restriction of Operations within the Bounds of a Memory Buffer in Kernel

Severity
7.8HIGHNVD
OSV6.7
EPSS
0.0%
top 91.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9
Latest updateApr 15

Description

A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

NVDlinux/linux_kernel4.205.4.180+3
Debianlinux/linux_kernel< 5.10.103-1+3
Ubuntulinux/linux_kernel< 4.4.0-234.268
CVEListV5linux/linux_kernelkernel 5.17
Palo Altopaloalto/pan-os

Also affects: Enterprise Linux 7.0, 8.0, 9.0

Patches

🔴Vulnerability Details

4
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-09-30
GHSA
GHSA-fqwg-v36p-p5p4: A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 22022-09-10
CVEList
CVE-2022-2964: A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 22022-09-09
OSV
CVE-2022-2964: A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 22022-09-09

📋Vendor Advisories

5
CISA ICS
ABB M2M Gateway2025-04-15
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Ubuntu
Linux kernel vulnerabilities2022-09-30
Red Hat
kernel: memory corruption in AX88179_178A based USB ethernet device.2022-03-21
Debian
CVE-2022-2964: linux - A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based US...2022
CVE-2022-2964 — Linux Kernel vulnerability | cvebase