kernel: network backend may cause Linux netfront to use freed SKBs (XSA-405)
Published Jul 5, 2022
7.8
HIGHCVSS 3.1
EPSS 0.35%
Description
network backend may cause Linux netfront to use freed SKBs While adding logic to support XDP (eXpress Data Path), a code label was moved in a way allowing for SKBs having references (pointers) retained for further processing to nevertheless be freed.
Affected products
No data.
Configuration 1
- ≥ 5.9 · ≤ 5.18
- n/a
Configuration 2
- 11.0
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-284.11.1.rt14.296.el9_2
Fixed · RHSA-2023:2148
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-284.11.1.rt14.296.el9_2 | Fixed | RHSA-2023:2148 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Keeping this flaw Moderate, because only a denial of service is possible (A:H) as result of memory leak problem. The memory leak can happen because instead of removing skb, keeping it in the networking stack forever. The CVSS score is higher, than usually for Moderate, because kept "C:H" and "I:H" too in case maybe potentially would be possible privilege escalation too.
References (11)
- http://www.openwall.com/lists/oss-security/2022/07/05/5 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://xenbits.xen.org/xsa/advisory-405.html x_refsource_CONFIRMPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2022-33743 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2107924 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-36782 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/drivers/net/xen-netfront.c?h=v5.19-rc7&id=f63c2c2032c2e3caad9add3b82cc6e91c376fd26
- https://nvd.nist.gov/vuln/detail/CVE-2022-33743
- https://www.cve.org/CVERecord?id=CVE-2022-33743
- https://www.debian.org/security/2022/dsa-5191 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.openwall.com/lists/oss-security/2022/07/05/5
- https://xenbits.xenproject.org/xsa/advisory-405.txt x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2022/07/05/5 | mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory | |
| http://xenbits.xen.org/xsa/advisory-405.html | x_refsource_CONFIRMPatchVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2022-33743 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2107924 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-36782 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/drivers/net/xen-netfront.c?h=v5.19-rc7&id=f63c2c2032c2e3caad9add3b82cc6e91c376fd26 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-33743 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-33743 | ||
| https://www.debian.org/security/2022/dsa-5191 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| https://www.openwall.com/lists/oss-security/2022/07/05/5 | ||
| https://xenbits.xenproject.org/xsa/advisory-405.txt | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.