cbcvebase.
CVE-2022-48807
published 2024-07-16

CVE-2022-48807: In the Linux kernel, the following vulnerability has been resolved: ice: Fix KASAN error in LAG NETDEV_UNREGISTER handler Currently, the same handler is called…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ice: Fix KASAN error in LAG NETDEV_UNREGISTER handler Currently, the same handler is called for both a NETDEV_BONDING_INFO LAG unlink notification as for a NETDEV_UNREGISTER call. This is causing a problem though, since the netdev_notifier_info passed has a different structure depending on which event is passed. The problem manifests as a call trace from a BUG: KASAN stack-out-of-bounds error. Fix this by creating a handler specific to NETDEV_UNREGISTER that only is passed valid elements in the netdev_notifier_info struct for the NETDEV_UNREGISTER event. Also included is the removal of an unbalanced dev_put on the peer_netdev and related braces.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.10-1 (bookworm)linux 5.16.10-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.14.16 < 5.155.15
linuxlinux>= 6a8b357278f5f8b9817147277ab8f12879dce8a8 < f9daedc3ab8f673e3a9374b91a89fbf1174df469f9daedc3ab8f673e3a9374b91a89fbf1174df469
linuxlinux>= 6a8b357278f5f8b9817147277ab8f12879dce8a8 < faa9bcf700ca1a0d09f92502a6b65d3ce313fb46faa9bcf700ca1a0d09f92502a6b65d3ce313fb46
linuxlinux>= 6a8b357278f5f8b9817147277ab8f12879dce8a8 < bea1898f65b9b7096cb4e73e97c83b94718f1fa1bea1898f65b9b7096cb4e73e97c83b94718f1fa1
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 5.14.16 < 5.155.15
linuxlinux_kernel>= 5.15.1 < 5.15.245.15.24
linuxlinux_kernel>= 5.16 < 5.16.105.16.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.