cbcvebase.
CVE-2022-49583
published 2025-02-26

CVE-2022-49583: In the Linux kernel, the following vulnerability has been resolved: iavf: Fix handling of dummy receive descriptors Fix memory leak caused by not handling…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.0th percentile
In the Linux kernel, the following vulnerability has been resolved: iavf: Fix handling of dummy receive descriptors Fix memory leak caused by not handling dummy receive descriptor properly. iavf_get_rx_buffer now sets the rx_buffer return value for dummy receive descriptors. Without this patch, when the hardware writes a dummy descriptor, iavf would not free the page allocated for the previous receive buffer. This is an unlikely event but can still happen. [Jesse: massaged commit message]

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.16-1 (bookworm)linux 5.18.16-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 5.1.20 < 5.25.2
linuxlinux>= 5.2.3 < 5.35.3
linuxlinux>= efa14c3985828da3163f5372137cb64d992b0f79 < d88d59faf4e6f9cc4767664206afdb999b10ec77d88d59faf4e6f9cc4767664206afdb999b10ec77
linuxlinux>= efa14c3985828da3163f5372137cb64d992b0f79 < c6af94324911ef0846af1a5ce5e049ca736db34bc6af94324911ef0846af1a5ce5e049ca736db34b
linuxlinux>= efa14c3985828da3163f5372137cb64d992b0f79 < 2918419c06088f6709ceb543feb01752779ade4c2918419c06088f6709ceb543feb01752779ade4c
linuxlinux>= efa14c3985828da3163f5372137cb64d992b0f79 < 6edb818732fc05fda495f5b3a749bd1cee01398b6edb818732fc05fda495f5b3a749bd1cee01398b
linuxlinux>= efa14c3985828da3163f5372137cb64d992b0f79 < a9f49e0060301a9bfebeca76739158d0cf91cdf6a9f49e0060301a9bfebeca76739158d0cf91cdf6
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 0 < 5.18.16-15.18.16-1
linuxlinux_kernel>= 5.1.20 < 5.25.2
linuxlinux_kernel>= 5.11 < 5.15.585.15.58
linuxlinux_kernel>= 5.16 < 5.18.155.18.15
linuxlinux_kernel>= 5.2.3 < 5.4.2085.4.208
linuxlinux_kernel>= 5.5 < 5.10.1345.10.134

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.