CVE-2022-48798
published 2024-07-16CVE-2022-48798: In the Linux kernel, the following vulnerability has been resolved: s390/cio: verify the driver availability for path_event call If no driver is attached to a…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
s390/cio: verify the driver availability for path_event call
If no driver is attached to a device or the driver does not provide the
path_event function, an FCES path-event on this device could end up in a
kernel-panic. Verify the driver availability before the path_event
function call.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.10-1 (bookworm) | linux 5.16.10-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 32ef938815c1fb42d65212aac860ab153a64de1a < fe990b7bf6ac93f1d850d076b8f0e758268aa4ab | fe990b7bf6ac93f1d850d076b8f0e758268aa4ab |
| linux | linux | >= 32ef938815c1fb42d65212aac860ab153a64de1a < a0619027f11590b2070624297530c34dc7f91bcd | a0619027f11590b2070624297530c34dc7f91bcd |
| linux | linux | >= 32ef938815c1fb42d65212aac860ab153a64de1a < dd9cb842fa9d90653a9b48aba52f89c069f3bc50 | dd9cb842fa9d90653a9b48aba52f89c069f3bc50 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 5.11 < 5.15.24 | 5.15.24 |
| linux | linux_kernel | >= 5.16 < 5.16.10 | 5.16.10 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 5.15.23/5.16.9 s390 path_event denial of service (fe990b7bf6ac/a0619027f115/dd9cb842fa9d / WID-SEC-2024-1625)
vuldb·2026-07-11·CVSS 5.5
CVE-2022-48798 [MEDIUM] Linux Kernel up to 5.15.23/5.16.9 s390 path_event denial of service (fe990b7bf6ac/a0619027f115/dd9cb842fa9d / WID-SEC-2024-1625)
A vulnerability marked as critical has been reported in Linux Kernel up to 5.15.23/5.16.9. This affects the function path_event of the component s390. The manipulation leads to denial of service.
This vulnerability is referenced as CVE-2022-48798. The attack needs to be initiated within the local network. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
GHSA-h4fq-wqr3-5hg3: In the Linux kernel, the following vulnerability has been resolved:
s390/cio: verify the driver availability for path_event call
If no driver is att
ghsa_unreviewed·2024-07-16
CVE-2022-48798 [MEDIUM] GHSA-h4fq-wqr3-5hg3: In the Linux kernel, the following vulnerability has been resolved:
s390/cio: verify the driver availability for path_event call
If no driver is att
In the Linux kernel, the following vulnerability has been resolved:
s390/cio: verify the driver availability for path_event call
If no driver is attached to a device or the driver does not provide the
path_event function, an FCES path-event on this device could end up in a
kernel-panic. Verify the driver availability before the path_event
function call.
OSV
CVE-2022-48798: In the Linux kernel, the following vulnerability has been resolved: s390/cio: verify the driver availability for path_event call If no driver is attac
osv·2024-07-16·CVSS 5.5
CVE-2022-48798 [MEDIUM] CVE-2022-48798: In the Linux kernel, the following vulnerability has been resolved: s390/cio: verify the driver availability for path_event call If no driver is attac
In the Linux kernel, the following vulnerability has been resolved: s390/cio: verify the driver availability for path_event call If no driver is attached to a device or the driver does not provide the path_event function, an FCES path-event on this device could end up in a kernel-panic. Verify the driver availability before the path_event function call.
Red Hat
kernel: s390/cio: verify the driver availability for path_event call
vendor_redhat·2024-07-16·CVSS 5.5
CVE-2022-48798 [MEDIUM] CWE-99 kernel: s390/cio: verify the driver availability for path_event call
kernel: s390/cio: verify the driver availability for path_event call
In the Linux kernel, the following vulnerability has been resolved:
s390/cio: verify the driver availability for path_event call
If no driver is attached to a device or the driver does not provide the
path_event function, an FCES path-event on this device could end up in a
kernel-panic. Verify the driver availability before the path_event
function call.
A vulnerability was found in the Linux kernel's S390 driver, where the path_event function can lead to a kernel panic if no driver is attached to a device or if the driver does not implement the function. This occurs when an FCES path-event is triggered without verifying the driver's availability first. The impact of this vulnerability can result in unexpected system cra
Debian
CVE-2022-48798: linux - In the Linux kernel, the following vulnerability has been resolved: s390/cio: v...
vendor_debian·2022·CVSS 5.5
CVE-2022-48798 [MEDIUM] CVE-2022-48798: linux - In the Linux kernel, the following vulnerability has been resolved: s390/cio: v...
In the Linux kernel, the following vulnerability has been resolved: s390/cio: verify the driver availability for path_event call If no driver is attached to a device or the driver does not provide the path_event function, an FCES path-event on this device could end up in a kernel-panic. Verify the driver availability before the path_event function call.
Scope: local
bookworm: resolved (fixed in 5.16.10-1)
bullseye: resolved
forky: resolved (fixed in 5.16.10-1)
sid: resolved (fixed in 5.16.10-1)
trixie: resolved (fixed in 5.16.10-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/a0619027f11590b2070624297530c34dc7f91bcdhttps://git.kernel.org/stable/c/dd9cb842fa9d90653a9b48aba52f89c069f3bc50https://git.kernel.org/stable/c/fe990b7bf6ac93f1d850d076b8f0e758268aa4abhttps://git.kernel.org/stable/c/a0619027f11590b2070624297530c34dc7f91bcdhttps://git.kernel.org/stable/c/dd9cb842fa9d90653a9b48aba52f89c069f3bc50https://git.kernel.org/stable/c/fe990b7bf6ac93f1d850d076b8f0e758268aa4ab
2024-07-16
Published