cbcvebase.
CVE-2022-48743
published 2024-06-20

CVE-2022-48743: In the Linux kernel, the following vulnerability has been resolved: net: amd-xgbe: Fix skb data length underflow There will be BUG_ON() triggered in…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.65%
47.5th percentile
In the Linux kernel, the following vulnerability has been resolved: net: amd-xgbe: Fix skb data length underflow There will be BUG_ON() triggered in include/linux/skbuff.h leading to intermittent kernel panic, when the skb length underflow is detected. Fix this by dropping the packet if such length underflows are seen because of inconsistencies in the hardware descriptors.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.7-1 (bookworm)linux 5.16.7-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.10.7 < 4.114.11
linuxlinux>= 4.4.58 < 4.54.5
linuxlinux>= 4.9.19 < 4.9.3004.9.300
linuxlinux>= 622c36f143fc9566ba49d7cec994c2da1182d9e2 < 617f9934bb37993b9813832516f318ba874bcb7d617f9934bb37993b9813832516f318ba874bcb7d
linuxlinux>= 622c36f143fc9566ba49d7cec994c2da1182d9e2 < 34aeb4da20f93ac80a6291a2dbe7b9c6460e9b2634aeb4da20f93ac80a6291a2dbe7b9c6460e9b26
linuxlinux>= 622c36f143fc9566ba49d7cec994c2da1182d9e2 < 9892742f035f7aa7dcd2bb0750effa486db895769892742f035f7aa7dcd2bb0750effa486db89576
linuxlinux>= 622c36f143fc9566ba49d7cec994c2da1182d9e2 < 4d3fcfe8464838b3920bc2b939d888e0b792934e4d3fcfe8464838b3920bc2b939d888e0b792934e
linuxlinux>= 622c36f143fc9566ba49d7cec994c2da1182d9e2 < db6fd92316a254be2097556f01bccecf560e53cedb6fd92316a254be2097556f01bccecf560e53ce
linuxlinux>= 622c36f143fc9566ba49d7cec994c2da1182d9e2 < e8f73f620fee5f52653ed2da360121e4446575c5e8f73f620fee5f52653ed2da360121e4446575c5
linuxlinux>= 622c36f143fc9566ba49d7cec994c2da1182d9e2 < 5aac9108a180fc06e28d4e7fb00247ce603b72ee5aac9108a180fc06e28d4e7fb00247ce603b72ee
linuxlinux>= fafc9555d87a19c78bcd43ed731c3a73bf0b37a9 < 9924c80bd484340191e586110ca22bff23a49f2e9924c80bd484340191e586110ca22bff23a49f2e
linuxlinux_kernel>= 0 < 5.10.103-15.10.103-1
linuxlinux_kernel>= 0 < 5.16.7-15.16.7-1
linuxlinux_kernel>= 0 < 5.16.7-15.16.7-1
linuxlinux_kernel>= 0 < 5.16.7-15.16.7-1
linuxlinux_kernel>= 4.11 < 4.14.2654.14.265
linuxlinux_kernel>= 4.15 < 4.19.2284.19.228
linuxlinux_kernel>= 4.20 < 5.4.1775.4.177
linuxlinux_kernel>= 4.9.19 < 4.9.3004.9.300
linuxlinux_kernel>= 5.11 < 5.15.205.15.20
linuxlinux_kernel>= 5.16 < 5.16.65.16.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.