CVE-2022-48934

In the Linux kernel, the following vulnerability has been resolved: nfp: flower: Fix a potential leak in nfp_tunnel_add_shared_mac() ida_simple_get() returns an id between min (0) and max (NFP_MAX_MAC_INDEX) inclusive. So NFP_MAX_MAC_INDEX (0xff) is a valid id. In order for the error handling path to work correctly, the 'invalid' value for 'ida_idx' should not be in the 0..NFP_MAX_MAC_INDEX range, inclusive. So set it to -1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

22 Aug 2024, 20:33

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux linux Kernel
Linux
CWE CWE-401
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/3a14d0888eb4b0045884126acc69abfb7b87814d - () https://git.kernel.org/stable/c/3a14d0888eb4b0045884126acc69abfb7b87814d - Patch
References () https://git.kernel.org/stable/c/4086d2433576baf85f0e538511df97c8101e0a10 - () https://git.kernel.org/stable/c/4086d2433576baf85f0e538511df97c8101e0a10 - Patch
References () https://git.kernel.org/stable/c/5ad5886f85b6bd893e3ed19013765fb0c243c069 - () https://git.kernel.org/stable/c/5ad5886f85b6bd893e3ed19013765fb0c243c069 - Patch
References () https://git.kernel.org/stable/c/9d8097caa73200710d52b9f4d9f430548f46a900 - () https://git.kernel.org/stable/c/9d8097caa73200710d52b9f4d9f430548f46a900 - Patch
References () https://git.kernel.org/stable/c/af4bc921d39dffdb83076e0a7eed1321242b7d87 - () https://git.kernel.org/stable/c/af4bc921d39dffdb83076e0a7eed1321242b7d87 - Patch

22 Aug 2024, 12:48

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: nfp: flower: corrige una fuga potencial en nfp_tunnel_add_shared_mac() ida_simple_get() devuelve una identificación entre min (0) y max (NFP_MAX_MAC_INDEX) incluida. Entonces NFP_MAX_MAC_INDEX (0xff) es una identificación válida. Para que la ruta de manejo de errores funcione correctamente, el valor 'no válido' para 'ida_idx' no debe estar en el rango 0..NFP_MAX_MAC_INDEX, incluida. Así que configúrelo en -1.

22 Aug 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-22 04:15

Updated : 2024-08-22 20:33


NVD link : CVE-2022-48934

Mitre link : CVE-2022-48934

CVE.ORG link : CVE-2022-48934


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime