cbcvebase.
CVE-2022-48648
published 2024-04-28

CVE-2022-48648: In the Linux kernel, the following vulnerability has been resolved: sfc: fix null pointer dereference in efx_hard_start_xmit Trying to get the channel from the…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: sfc: fix null pointer dereference in efx_hard_start_xmit Trying to get the channel from the tx_queue variable here is wrong because we can only be here if tx_queue is NULL, so we shouldn't dereference it. As the above comment in the code says, this is very unlikely to happen, but it's wrong anyway so let's fix it. I hit this issue because of a different bug that caused tx_queue to be NULL. If that happens, this is the error message that we get here: BUG: unable to handle kernel NULL pointer dereference at 0000000000000020 [...] RIP: 0010:efx_hard_start_xmit+0x153/0x170 [sfc]

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= 12804793b17c0e19115a90d98f2f3df0cb79e233 < b3b41d4d95d3822b2e459ecbc80d030ea6aec5e7b3b41d4d95d3822b2e459ecbc80d030ea6aec5e7
linuxlinux>= 12804793b17c0e19115a90d98f2f3df0cb79e233 < 8547c7bfc0617e7184e4da65b9b96681fcfe99988547c7bfc0617e7184e4da65b9b96681fcfe9998
linuxlinux>= 12804793b17c0e19115a90d98f2f3df0cb79e233 < b3b952168ee1f220ba729fa100fd9d5aa752eb03b3b952168ee1f220ba729fa100fd9d5aa752eb03
linuxlinux>= 12804793b17c0e19115a90d98f2f3df0cb79e233 < 0a242eb2913a4aa3d6fbdb86559f27628e9466f30a242eb2913a4aa3d6fbdb86559f27628e9466f3
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.148-15.10.148-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 5.10 < 5.10.1465.10.146
linuxlinux_kernel>= 5.11 < 5.15.715.15.71
linuxlinux_kernel>= 5.16 < 5.19.125.19.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.