netfilter: ebtables: fix memory leak when blob is malformed
Published Apr 28, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.24%
Description
The bug fix was incomplete, it "replaced" crash with a memory leak. The old code had an assignment to "ret" embedded into the conditional, restore this.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- ≥ 4.14.292, < 4.14.295
- ≥ 4.19.257, < 4.19.260
- ≥ 5.10.140, < 5.10.146
- ≥ 5.15.64, < 5.15.71
- ≥ 5.19.6, < 5.19.12
- ≥ 5.4.212, < 5.4.215
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 4.14.292 · < 4.14.295
- ≥ 4.19.257 · < 4.19.260
- ≥ 5.4.212 · < 5.4.215
- ≥ 5.10.140 · < 5.10.146
- ≥ 5.15.64 · < 5.15.71
- ≥ 5.19.6 · < 5.19.12
No data.
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2022-48641 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2277825 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-51336 Advisory
- https://git.kernel.org/stable/c/11ebf32fde46572b0aaf3c2bdd97d923ef5a03ab Patch
- https://git.kernel.org/stable/c/1e98318af2f163eadaff815abcef38d27ca92c1e Patch
- https://git.kernel.org/stable/c/38cf372b17f0a5f35c1b716a100532d539f0eb33 Patch
- https://git.kernel.org/stable/c/62ce44c4fff947eebdf10bb582267e686e6835c9 Patch
- https://git.kernel.org/stable/c/754e8b74281dd54a324698803483f47cf3355ae1 Patch
- https://git.kernel.org/stable/c/d5917b7af7cae0e2804f9d127a03268035098b7f Patch
- https://git.kernel.org/stable/c/ebd97dbe3c55d68346b9c5fb00634a7f5b10bbee Patch
- https://lore.kernel.org/linux-cve-announce/2024042856-CVE-2022-48641-531f@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48641
- https://www.cve.org/CVERecord?id=CVE-2022-48641
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data