Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-48934— nfp: flower: Fix a potential leak in nfp_tunnel_add_shared_mac()

AI Predicted 5.5 Difficulty: Moderate EPSS 0.21% · P11

Possible ATT&CK Techniques 1AI

T1564.008 · Email Hiding Rules

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinux20cce88650981ec504d328dbbdd004d991eb8535< 5ad5886f85b6bd893e3ed19013765fb0c243c069affected
20cce88650981ec504d328dbbdd004d991eb8535< af4bc921d39dffdb83076e0a7eed1321242b7d87affected
20cce88650981ec504d328dbbdd004d991eb8535< 9d8097caa73200710d52b9f4d9f430548f46a900affected
20cce88650981ec504d328dbbdd004d991eb8535< 4086d2433576baf85f0e538511df97c8101e0a10affected
20cce88650981ec504d328dbbdd004d991eb8535< 3a14d0888eb4b0045884126acc69abfb7b87814daffected
5.1affected
< 5.1unaffected
5.4.182≤ 5.4.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-48934

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
nfp: flower: Fix a potential leak in nfp_tunnel_add_shared_mac()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nfp: flower: Fix a potential leak in nfp_tunnel_add_shared_mac() ida_simple_get() returns an id between min (0) and max (NFP_MAX_MAC_INDEX) inclusive. So NFP_MAX_MAC_INDEX (0xff) is a valid id. In order for the error handling path to work correctly, the 'invalid' value for 'ida_idx' should not be in the 0..NFP_MAX_MAC_INDEX range, inclusive. So set it to -1.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在nfp_tunnel_add_shared_mac函数中存在内存泄漏问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 20cce88650981ec504d328dbbdd004d991eb8535 ~ 5ad5886f85b6bd893e3ed19013765fb0c243c069 -
LinuxLinux 5.1 -

II. Public POCs for CVE-2022-48934

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-48934

登录查看更多情报信息。

Other References for CVE-2022-48934 (5)

Same Patch Batch · Linux · 2024-08-22 · 42 CVEs total

CVE-2022-489418.8 HIGHice: fix concurrent reset and removal of VFs
CVE-2022-489198.8 HIGHcifs: fix double free race when mount fails in cifs_get_root()
CVE-2022-489237.8 HIGHbtrfs: prevent copying too big compressed lzo segment
CVE-2022-489257.8 HIGHRDMA/cma: Do not change route.addr.src_addr outside state checks
CVE-2022-489277.8 HIGHiio: adc: tsc2046: fix memory corruption by preventing array overflow
CVE-2022-489137.8 HIGHblktrace: fix use after free for struct blk_trace
CVE-2022-489127.8 HIGHnetfilter: fix use-after-free in __nf_register_net_hook()
CVE-2022-489117.8 HIGHnetfilter: nf_queue: fix possible use-after-free
CVE-2022-489327.8 HIGHnet/mlx5: DR, Fix slab-out-of-bounds in mlx5_cmd_dr_create_fte
CVE-2022-489357.8 HIGHnetfilter: nf_tables: unregister flowtable hooks on netns exit
CVE-2022-489407.8 HIGHbpf: Fix crash due to incorrect copy_map_value
CVE-2022-489437.1 HIGHKVM: x86/mmu: make apf token non-zero to fix bug
CVE-2022-48931configfs: fix a race in configfs_{,un}register_subsystem()
CVE-2022-48930RDMA/ib_srp: Fix a deadlock
CVE-2022-48933netfilter: nf_tables: fix memory leak during stateful obj update
CVE-2022-48937io_uring: add a schedule point in io_add_buffers()
CVE-2022-48929bpf: Fix crash due to out of bounds access into reg2btf_ids.
CVE-2022-48928iio: adc: men_z188_adc: Fix a resource leak in an error handling path
CVE-2022-48938CDC-NCM: avoid overflow in sanity checking
CVE-2022-48926usb: gadget: rndis: add spinlock for rndis response list

Showing top 20 of 42 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-48934

No comments yet


Leave a comment