cbcvebase.
CVE-2022-49725
published 2025-02-26

CVE-2022-49725: In the Linux kernel, the following vulnerability has been resolved: i40e: Fix call trace in setup_tx_descriptors After PF reset and ethtool -t there was call…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.30%
22.2th percentile
In the Linux kernel, the following vulnerability has been resolved: i40e: Fix call trace in setup_tx_descriptors After PF reset and ethtool -t there was call trace in dmesg sometimes leading to panic. When there was some time, around 5 seconds, between reset and test there were no errors. Problem was that pf reset calls i40e_vsi_close in prep_for_reset and ethtool -t calls i40e_vsi_close in diag_test. If there was not enough time between those commands the second i40e_vsi_close starts before previous i40e_vsi_close was done which leads to crash. Add check to diag_test if pf is in reset and don't start offline tests if it is true. Add netif_info("testing failed") into unhappy path of i40e_diag_test()

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= e17bc411aea8fbebc51857037f104ab09f765120 < 5ba9956ca57e361fb13ea369bb753eb33177acc75ba9956ca57e361fb13ea369bb753eb33177acc7
linuxlinux>= e17bc411aea8fbebc51857037f104ab09f765120 < 15950157e2c24865b696db1c9ccc72743ae0e96715950157e2c24865b696db1c9ccc72743ae0e967
linuxlinux>= e17bc411aea8fbebc51857037f104ab09f765120 < ff6e03fe84bc917bb0c907d02de668c2fe101712ff6e03fe84bc917bb0c907d02de668c2fe101712
linuxlinux>= e17bc411aea8fbebc51857037f104ab09f765120 < 814092927a215f5ca6c08249ec72a205e0b473cd814092927a215f5ca6c08249ec72a205e0b473cd
linuxlinux>= e17bc411aea8fbebc51857037f104ab09f765120 < 0a4e5a3dc5e41212870e6043895ae02455c93f630a4e5a3dc5e41212870e6043895ae02455c93f63
linuxlinux>= e17bc411aea8fbebc51857037f104ab09f765120 < 322271351b0e41565171e4cce70ea41854fac115322271351b0e41565171e4cce70ea41854fac115
linuxlinux>= e17bc411aea8fbebc51857037f104ab09f765120 < fd5855e6b1358e816710afee68a1d2bc685176cafd5855e6b1358e816710afee68a1d2bc685176ca
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 4.15 < 4.19.2494.19.249
linuxlinux_kernel>= 4.2 < 4.14.2854.14.285
linuxlinux_kernel>= 4.20 < 5.4.2005.4.200
linuxlinux_kernel>= 5.11 < 5.15.495.15.49
linuxlinux_kernel>= 5.16 < 5.18.65.18.6
linuxlinux_kernel>= 5.5 < 5.10.1245.10.124

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.