In the Linux kernel, the following vulnerability has been resolved:
igb: Initialize mailbox message for VF reset
When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48949.json"
}[
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@367e1e3399dbc56fc669740c4ab60e35da632b0e",
"signature_type": "Line",
"id": "CVE-2022-48949-152ee34e"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@51fd5ede7ed42f272682a0c33d6f0767b3484a3d",
"signature_type": "Line",
"id": "CVE-2022-48949-173face0"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"deprecated": false,
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f2479c3daaabccbac6c343a737615d0c595c6dc4",
"signature_type": "Function",
"id": "CVE-2022-48949-25b3b47c"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"deprecated": false,
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c383c7c35c7bc15e07a04eefa060a8a80cbeae29",
"signature_type": "Function",
"id": "CVE-2022-48949-34e0a4ce"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"deprecated": false,
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@367e1e3399dbc56fc669740c4ab60e35da632b0e",
"signature_type": "Function",
"id": "CVE-2022-48949-4c54462d"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ef1d739dd1f362aec081278ff92f943c31eb177a",
"signature_type": "Line",
"id": "CVE-2022-48949-4ee4698a"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c581439a977545d61849a72e8ed631cfc8a2a3c1",
"signature_type": "Line",
"id": "CVE-2022-48949-529f73a1"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"deprecated": false,
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c581439a977545d61849a72e8ed631cfc8a2a3c1",
"signature_type": "Function",
"id": "CVE-2022-48949-76979b89"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a6629659af3f5c6a91e3914ea62554c975ab77f4",
"signature_type": "Line",
"id": "CVE-2022-48949-7c8f9278"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c383c7c35c7bc15e07a04eefa060a8a80cbeae29",
"signature_type": "Line",
"id": "CVE-2022-48949-bb5ad7a7"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de5dc44370fbd6b46bd7f1a1e00369be54a041c8",
"signature_type": "Line",
"id": "CVE-2022-48949-d6aff224"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"deprecated": false,
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@51fd5ede7ed42f272682a0c33d6f0767b3484a3d",
"signature_type": "Function",
"id": "CVE-2022-48949-d6c0a509"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"deprecated": false,
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de5dc44370fbd6b46bd7f1a1e00369be54a041c8",
"signature_type": "Function",
"id": "CVE-2022-48949-da0d94b3"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f2479c3daaabccbac6c343a737615d0c595c6dc4",
"signature_type": "Line",
"id": "CVE-2022-48949-e84706d0"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"deprecated": false,
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a6629659af3f5c6a91e3914ea62554c975ab77f4",
"signature_type": "Function",
"id": "CVE-2022-48949-f4e23bdd"
},
{
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"deprecated": false,
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ef1d739dd1f362aec081278ff92f943c31eb177a",
"signature_type": "Function",
"id": "CVE-2022-48949-f9b9a3d3"
}
]