net: amd-xgbe: Fix skb data length underflow
Published Jun 20, 2024
8.1
HIGHCVSS 3.1
EPSS 0.65%
Description
There will be BUG_ON() triggered in include/linux/skbuff.h leading to intermittent kernel panic, when the skb length underflow is detected.
Fix this by dropping the packet if such length underflows are seen because of inconsistencies in the hardware descriptors.
Affected products
-
Affected
- ≥ 4.10.7, < 4.11
- ≥ 4.4.58, < 4.5
- ≥ 4.9.19, < 4.9.300
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 4.11
Unaffected
- ≥ 0, < 4.11
- ≥ 4.14.265, ≤ 4.14.*
- ≥ 4.19.228, ≤ 4.19.*
- ≥ 4.9.300, ≤ 4.9.*
- ≥ 5.10.97, ≤ 5.10.*
- ≥ 5.15.20, ≤ 5.15.*
- ≥ 5.16.6, ≤ 5.16.*
- 5.17
- ≥ 5.4.177, ≤ 5.4.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- ≥ 4.9.19 · < 4.9.300
- ≥ 4.11 · < 4.14.265
- ≥ 4.15 · < 4.19.228
- ≥ 4.20 · < 5.4.177
- ≥ 5.5 · < 5.10.97
- ≥ 5.11 · < 5.15.20
- ≥ 5.16 · < 5.16.6
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.16.1.el8_10
Fixed · RHSA-2024:5101
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.16.1.rt7.357.el8_10
Fixed · RHSA-2024:5102
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.113.1.el8_6
Fixed · RHSA-2024:4902
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
kernel-0:4.18.0-372.113.1.el8_6
Fixed · RHSA-2024:4902
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
kernel-0:4.18.0-372.113.1.el8_6
Fixed · RHSA-2024:4902
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.70.1.el8_8
Fixed · RHSA-2024:6206
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.28.1.el9_4
Fixed · RHSA-2024:4928
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.28.1.el9_4
Fixed · RHSA-2024:4928
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.75.1.el9_2
Fixed · RHSA-2024:4823
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.75.1.rt14.360.el9_2
Fixed · RHSA-2024:4831
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.16.1.el8_10 | Fixed | RHSA-2024:5101 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.16.1.rt7.357.el8_10 | Fixed | RHSA-2024:5102 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.113.1.el8_6 | Fixed | RHSA-2024:4902 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | kernel-0:4.18.0-372.113.1.el8_6 | Fixed | RHSA-2024:4902 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | kernel-0:4.18.0-372.113.1.el8_6 | Fixed | RHSA-2024:4902 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.70.1.el8_8 | Fixed | RHSA-2024:6206 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.28.1.el9_4 | Fixed | RHSA-2024:4928 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.28.1.el9_4 | Fixed | RHSA-2024:4928 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.75.1.el9_2 | Fixed | RHSA-2024:4823 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.75.1.rt14.360.el9_2 | Fixed | RHSA-2024:4831 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2022-48743 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2293316 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53622 Advisory
- https://git.kernel.org/stable/c/34aeb4da20f93ac80a6291a2dbe7b9c6460e9b26 Mailing ListPatch
- https://git.kernel.org/stable/c/4d3fcfe8464838b3920bc2b939d888e0b792934e Mailing ListPatch
- https://git.kernel.org/stable/c/5aac9108a180fc06e28d4e7fb00247ce603b72ee Mailing ListPatch
- https://git.kernel.org/stable/c/617f9934bb37993b9813832516f318ba874bcb7d Mailing ListPatch
- https://git.kernel.org/stable/c/9892742f035f7aa7dcd2bb0750effa486db89576 Mailing ListPatch
- https://git.kernel.org/stable/c/9924c80bd484340191e586110ca22bff23a49f2e Mailing ListPatch
- https://git.kernel.org/stable/c/db6fd92316a254be2097556f01bccecf560e53ce Mailing ListPatch
- https://git.kernel.org/stable/c/e8f73f620fee5f52653ed2da360121e4446575c5 Mailing ListPatch
- https://lore.kernel.org/linux-cve-announce/2024062003-CVE-2022-48743-ee30@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48743
- https://www.cve.org/CVERecord?id=CVE-2022-48743
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data