CVE-2022-48743
Last modified
CVE-2022-48743 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: net: amd-xgbe: Fix skb data length underflow There will be BUG_ON() triggered in include/linux/skbuff.h leading to intermittent kernel panic, when the skb length underflow is detected. Fix this by dropping the packet if such length underflows are seen because of inconsistencies in the hardware descriptors.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: net: amd-xgbe: Fix skb data length underflow There will be BUG_ON() triggered in include/linux/skbuff.h leading to intermittent kernel panic, when the skb length underflow is detected. Fix this by dropping the packet if such length underflows are seen because of inconsistencies in the hardware descriptors.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.9.19, < 4.9.300 |
| Linux | Linux Kernel | >= 4.11, < 4.14.265 |
| Linux | Linux Kernel | >= 4.15, < 4.19.228 |
| Linux | Linux Kernel | >= 4.20, < 5.4.177 |
| Linux | Linux Kernel | >= 5.5, < 5.10.97 |
| Linux | Linux Kernel | >= 5.11, < 5.15.20 |
| Linux | Linux Kernel | >= 5.16, < 5.16.6 |
References
- https://git.kernel.org/stable/c/34aeb4da20f93ac80a6291a2dbe7b9c6460e9b26Mailing List, Patch
- https://git.kernel.org/stable/c/4d3fcfe8464838b3920bc2b939d888e0b792934eMailing List, Patch
- https://git.kernel.org/stable/c/5aac9108a180fc06e28d4e7fb00247ce603b72eeMailing List, Patch
- https://git.kernel.org/stable/c/617f9934bb37993b9813832516f318ba874bcb7dMailing List, Patch
- https://git.kernel.org/stable/c/9892742f035f7aa7dcd2bb0750effa486db89576Mailing List, Patch
- https://git.kernel.org/stable/c/9924c80bd484340191e586110ca22bff23a49f2eMailing List, Patch
- https://git.kernel.org/stable/c/db6fd92316a254be2097556f01bccecf560e53ceMailing List, Patch
- https://git.kernel.org/stable/c/e8f73f620fee5f52653ed2da360121e4446575c5Mailing List, Patch
- https://git.kernel.org/stable/c/34aeb4da20f93ac80a6291a2dbe7b9c6460e9b26Mailing List, Patch
- https://git.kernel.org/stable/c/4d3fcfe8464838b3920bc2b939d888e0b792934eMailing List, Patch
- https://git.kernel.org/stable/c/5aac9108a180fc06e28d4e7fb00247ce603b72eeMailing List, Patch
- https://git.kernel.org/stable/c/617f9934bb37993b9813832516f318ba874bcb7dMailing List, Patch
- https://git.kernel.org/stable/c/9892742f035f7aa7dcd2bb0750effa486db89576Mailing List, Patch
- https://git.kernel.org/stable/c/9924c80bd484340191e586110ca22bff23a49f2eMailing List, Patch
- https://git.kernel.org/stable/c/db6fd92316a254be2097556f01bccecf560e53ceMailing List, Patch
- https://git.kernel.org/stable/c/e8f73f620fee5f52653ed2da360121e4446575c5Mailing List, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-48743?
How severe is CVE-2022-48743?
How do I fix CVE-2022-48743?
Are you affected by CVE-2022-48743?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
