CVE-2022-49654
published 2025-02-26CVE-2022-49654: In the Linux kernel, the following vulnerability has been resolved: net: dsa: qca8k: reset cpu port on MTU change It was discovered that the Documentation…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: qca8k: reset cpu port on MTU change
It was discovered that the Documentation lacks of a fundamental detail
on how to correctly change the MAX_FRAME_SIZE of the switch.
In fact if the MAX_FRAME_SIZE is changed while the cpu port is on, the
switch panics and cease to send any packet. This cause the mgmt ethernet
system to not receive any packet (the slow fallback still works) and
makes the device not reachable. To recover from this a switch reset is
required.
To correctly handle this, turn off the cpu ports before changing the
MAX_FRAME_SIZE and turn on again after the value is applied.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.14-1 (bookworm) | linux 5.18.14-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= f58d2598cf70d41f73e761b62a114d2e8f94a676 < 188c798f3c2554fa0d7147e9b97baf144b817019 | 188c798f3c2554fa0d7147e9b97baf144b817019 |
| linux | linux | >= f58d2598cf70d41f73e761b62a114d2e8f94a676 < 1993f5a06736ada59dd54b50dc96755a38796ee5 | 1993f5a06736ada59dd54b50dc96755a38796ee5 |
| linux | linux | >= f58d2598cf70d41f73e761b62a114d2e8f94a676 < 386228c694bf1e7a7688e44412cb33500b0ac585 | 386228c694bf1e7a7688e44412cb33500b0ac585 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 5.16 < 5.18.11 | 5.18.11 |
| linux | linux_kernel | >= 5.9 < 5.15.54 | 5.15.54 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-72j6-jfmc-mmvr: In the Linux kernel, the following vulnerability has been resolved:
net: dsa: qca8k: reset cpu port on MTU change
It was discovered that the Documen
ghsa_unreviewed·2025-10-23
CVE-2022-49654 [MEDIUM] GHSA-72j6-jfmc-mmvr: In the Linux kernel, the following vulnerability has been resolved:
net: dsa: qca8k: reset cpu port on MTU change
It was discovered that the Documen
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: qca8k: reset cpu port on MTU change
It was discovered that the Documentation lacks of a fundamental detail
on how to correctly change the MAX_FRAME_SIZE of the switch.
In fact if the MAX_FRAME_SIZE is changed while the cpu port is on, the
switch panics and cease to send any packet. This cause the mgmt ethernet
system to not receive any packet (the slow fallback still works) and
makes the device not reachable. To recover from this a switch reset is
required.
To correctly handle this, turn off the cpu ports before changing the
MAX_FRAME_SIZE and turn on again after the value is applied.
OSV
CVE-2022-49654: In the Linux kernel, the following vulnerability has been resolved: net: dsa: qca8k: reset cpu port on MTU change It was discovered that the Documenta
osv·2025-02-26·CVSS 5.5
CVE-2022-49654 [MEDIUM] CVE-2022-49654: In the Linux kernel, the following vulnerability has been resolved: net: dsa: qca8k: reset cpu port on MTU change It was discovered that the Documenta
In the Linux kernel, the following vulnerability has been resolved: net: dsa: qca8k: reset cpu port on MTU change It was discovered that the Documentation lacks of a fundamental detail on how to correctly change the MAX_FRAME_SIZE of the switch. In fact if the MAX_FRAME_SIZE is changed while the cpu port is on, the switch panics and cease to send any packet. This cause the mgmt ethernet system to not receive any packet (the slow fallback still works) and makes the device not reachable. To recover from this a switch reset is required. To correctly handle this, turn off the cpu ports before changing the MAX_FRAME_SIZE and turn on again after the value is applied.
Red Hat
kernel: net: dsa: qca8k: reset cpu port on MTU change
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49654 [MEDIUM] kernel: net: dsa: qca8k: reset cpu port on MTU change
kernel: net: dsa: qca8k: reset cpu port on MTU change
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: qca8k: reset cpu port on MTU change
It was discovered that the Documentation lacks of a fundamental detail
on how to correctly change the MAX_FRAME_SIZE of the switch.
In fact if the MAX_FRAME_SIZE is changed while the cpu port is on, the
switch panics and cease to send any packet. This cause the mgmt ethernet
system to not receive any packet (the slow fallback still works) and
makes the device not reachable. To recover from this a switch reset is
required.
To correctly handle this, turn off the cpu ports before changing the
MAX_FRAME_SIZE and turn on again after the value is applied.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: ker
Debian
CVE-2022-49654: linux - In the Linux kernel, the following vulnerability has been resolved: net: dsa: q...
vendor_debian·2022·CVSS 5.5
CVE-2022-49654 [MEDIUM] CVE-2022-49654: linux - In the Linux kernel, the following vulnerability has been resolved: net: dsa: q...
In the Linux kernel, the following vulnerability has been resolved: net: dsa: qca8k: reset cpu port on MTU change It was discovered that the Documentation lacks of a fundamental detail on how to correctly change the MAX_FRAME_SIZE of the switch. In fact if the MAX_FRAME_SIZE is changed while the cpu port is on, the switch panics and cease to send any packet. This cause the mgmt ethernet system to not receive any packet (the slow fallback still works) and makes the device not reachable. To recover from this a switch reset is required. To correctly handle this, turn off the cpu ports before changing the MAX_FRAME_SIZE and turn on again after the value is applied.
Scope: local
bookworm: resolved (fixed in 5.18.14-1)
bullseye: open
forky: resolved (fixed in 5.18.14-1)
sid: resolved (fixed in 5
No detection rules found.
No public exploits indexed.
2025-02-26
Published