In the Linux kernel, the following vulnerability has been resolved:
igb: Initialize mailbox message for VF reset
When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48949.json"
}[
{
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"id": "CVE-2022-48949-152ee34e",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@367e1e3399dbc56fc669740c4ab60e35da632b0e",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"id": "CVE-2022-48949-173face0",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@51fd5ede7ed42f272682a0c33d6f0767b3484a3d",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"id": "CVE-2022-48949-25b3b47c",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f2479c3daaabccbac6c343a737615d0c595c6dc4",
"deprecated": false,
"signature_type": "Function"
},
{
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"id": "CVE-2022-48949-34e0a4ce",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c383c7c35c7bc15e07a04eefa060a8a80cbeae29",
"deprecated": false,
"signature_type": "Function"
},
{
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"id": "CVE-2022-48949-4c54462d",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@367e1e3399dbc56fc669740c4ab60e35da632b0e",
"deprecated": false,
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"id": "CVE-2022-48949-4ee4698a",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ef1d739dd1f362aec081278ff92f943c31eb177a",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"id": "CVE-2022-48949-529f73a1",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c581439a977545d61849a72e8ed631cfc8a2a3c1",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"id": "CVE-2022-48949-76979b89",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c581439a977545d61849a72e8ed631cfc8a2a3c1",
"deprecated": false,
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"id": "CVE-2022-48949-7c8f9278",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a6629659af3f5c6a91e3914ea62554c975ab77f4",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"id": "CVE-2022-48949-bb5ad7a7",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c383c7c35c7bc15e07a04eefa060a8a80cbeae29",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"id": "CVE-2022-48949-d6aff224",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de5dc44370fbd6b46bd7f1a1e00369be54a041c8",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"id": "CVE-2022-48949-d6c0a509",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@51fd5ede7ed42f272682a0c33d6f0767b3484a3d",
"deprecated": false,
"signature_type": "Function"
},
{
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"id": "CVE-2022-48949-da0d94b3",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de5dc44370fbd6b46bd7f1a1e00369be54a041c8",
"deprecated": false,
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
],
"threshold": 0.9
},
"id": "CVE-2022-48949-e84706d0",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f2479c3daaabccbac6c343a737615d0c595c6dc4",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"id": "CVE-2022-48949-f4e23bdd",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a6629659af3f5c6a91e3914ea62554c975ab77f4",
"deprecated": false,
"signature_type": "Function"
},
{
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"id": "CVE-2022-48949-f9b9a3d3",
"signature_version": "v1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ef1d739dd1f362aec081278ff92f943c31eb177a",
"deprecated": false,
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48949.json"