First published: Mon Oct 21 2024(Updated: )
In the Linux kernel, the following vulnerability has been resolved: igb: Initialize mailbox message for VF reset When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.
Credit: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=4.0<4.14.303 | |
Linux Kernel | >=4.15<4.19.270 | |
Linux Kernel | >=4.20<5.4.229 | |
Linux Kernel | >=5.5<5.10.161 | |
Linux Kernel | >=5.11<5.15.85 | |
Linux Kernel | >=5.16<6.0.15 | |
Linux Kernel | =6.1 | |
Linux Kernel | =6.1-rc1 | |
Linux Kernel | =6.1-rc2 | |
Linux Kernel | =6.1-rc3 | |
Linux Kernel | =6.1-rc4 | |
Linux Kernel | =6.1-rc5 | |
Linux Kernel | =6.1-rc6 | |
Linux Kernel | =6.1-rc7 | |
Linux Kernel | =6.1-rc8 | |
Linux Kernel | =6.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48949 is classified as a high severity vulnerability in the Linux kernel.
To fix CVE-2022-48949, upgrade to a patched version of the Linux kernel as specified by the vendor.
CVE-2022-48949 affects various versions of the Linux kernel from 4.0 to 6.1.1.
CVE-2022-48949 impacts the igb driver due to improper initialization of mailbox messages.
Yes, CVE-2022-48949 could potentially allow an attacker to exploit the vulnerability remotely under certain conditions.