Linux Kernel skb macvlan.c macvlan_handle_frame memory leak
Published Oct 16, 2022
7.5
HIGHCVSS 3.1
EPSS 1.00%
Description
A vulnerability classified as problematic was found in Linux Kernel. This vulnerability affects the function macvlan_handle_frame of the file drivers/net/macvlan.c of the component skb. The manipulation leads to memory leak. The attack can be initiated remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211024.
Affected products
- ≥ 5.13 · < 5.15.35
- ≥ 5.16 · < 5.17.4
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
No shipped kernel versions were seen affected with this problem. The affected patch was not consumed on RHEL8 or below kernel.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-3526 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2161341 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42892 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/pabeni/net-next.git/commit/?id=e16b859872b87650bb55b12cca5a5fcdc49c1442 Mailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3526
- https://vuldb.com/?id.211024 Permissions RequiredThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-3526
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3526 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2161341 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42892 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/pabeni/net-next.git/commit/?id=e16b859872b87650bb55b12cca5a5fcdc49c1442 | Mailing ListPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3526 | ||
| https://vuldb.com/?id.211024 | Permissions RequiredThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-3526 |
Change history (0)
No recorded changes yet.