ravb: Fix potential use-after-free in ravb_rx_gbeth()
Published Oct 21, 2024
8.8
HIGHCVSS 3.1
EPSS 0.31%
Description
The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.16StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.16
- Version 6.0.13StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.16 · < 6.0.13
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-48964 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320717 Issue Tracking
- https://git.kernel.org/stable/c/5a5a3e564de6a8db987410c5c2f4748d50ea82b8 Patch
- https://git.kernel.org/stable/c/e63c681494dcc0527c625a0a4f59bf10259f5ee0 Patch
- https://lore.kernel.org/linux-cve-announce/2024102143-CVE-2022-48964-8230@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48964
- https://www.cve.org/CVERecord?id=CVE-2022-48964
Change history (0)
No recorded changes yet.