cbcvebase.
CVE-2022-3643
published 2022-12-07

CVE-2022-3643: Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network…

PriorityP428medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.46%
37.9th percentile
Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to be an (unwritten?) assumption in the rest of the Linux network stack that packet protocol headers are all contained within the linear section of the SKB and some NICs behave badly if this is not the case. This has been reported to occur with Cisco (enic) and Broadcom NetXtrem II BCM5780 (bnx2x) though it may be an issue with other NICs/drivers as well. In case the frontend is sending requests with split headers, netback will forward those violating above mentioned assumption to the networking core, resulting in said misbehavior.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 4.15.0-202.2134.15.0-202.213
linuxlinux_kernel>= 0 < 5.4.0-137.1545.4.0-137.154
linuxlinux_kernel>= 0 < 5.15.0-58.645.15.0-58.64
linuxlinux_kernel>= 0 < 4.4.0-246.2804.4.0-246.280
linuxlinux_kernel>= 0 < 4.4.0-236.2704.4.0-236.270
linuxlinux_kernel>= 0 < 4.15.0-219.2304.15.0-219.230
linuxlinux_kernel>= 0 < 5.4.0-165.1825.4.0-165.182
linuxlinux_kernel>= 0 < 5.15.0-87.975.15.0-87.97
linuxlinux_kernel>= 3.19 < 4.9.3364.9.336
linuxlinux_kernel>= 4.10 < 4.14.3024.14.302
linuxlinux_kernel>= 4.15 < 4.19.2694.19.269
linuxlinux_kernel>= 4.20 < 5.4.2275.4.227
linuxlinux_kernel>= 5.11 < 5.15.835.15.83
linuxlinux_kernel>= 5.16 < 6.0.136.0.13
linuxlinux_kernel>= 5.5 < 5.10.1595.10.159

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
osv6.7MEDIUM
cisa7.8HIGH
vendor_ubuntu6.7MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.