CVE-2022-48807

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/07/2024
Last modified:
25/09/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ice: Fix KASAN error in LAG NETDEV_UNREGISTER handler<br /> <br /> Currently, the same handler is called for both a NETDEV_BONDING_INFO<br /> LAG unlink notification as for a NETDEV_UNREGISTER call. This is<br /> causing a problem though, since the netdev_notifier_info passed has<br /> a different structure depending on which event is passed. The problem<br /> manifests as a call trace from a BUG: KASAN stack-out-of-bounds error.<br /> <br /> Fix this by creating a handler specific to NETDEV_UNREGISTER that only<br /> is passed valid elements in the netdev_notifier_info struct for the<br /> NETDEV_UNREGISTER event.<br /> <br /> Also included is the removal of an unbalanced dev_put on the peer_netdev<br /> and related braces.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.14.16 (including) 5.15 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.15.1 (including) 5.15.24 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 5.16.10 (excluding)
cpe:2.3:o:linux:linux_kernel:5.15:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.17:rc3:*:*:*:*:*:*