CVE-2022-48949: igb: Initialize mailbox message for VF reset
In the Linux kernel, the following vulnerability has been resolved:
igb: Initialize mailbox message for VF reset
When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-48949?
CVE-2022-48949 is classified as a high severity vulnerability in the Linux kernel.
How do I fix CVE-2022-48949?
To fix CVE-2022-48949, upgrade to a patched version of the Linux kernel as specified by the vendor.
What versions of the Linux kernel are affected by CVE-2022-48949?
CVE-2022-48949 affects various versions of the Linux kernel from 4.0 to 6.1.1.
What components are impacted by CVE-2022-48949?
CVE-2022-48949 impacts the igb driver due to improper initialization of mailbox messages.
Can CVE-2022-48949 be exploited remotely?
Yes, CVE-2022-48949 could potentially allow an attacker to exploit the vulnerability remotely under certain conditions.