In the Linux kernel, the following vulnerability has been resolved:
igb: Initialize mailbox message for VF reset
When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.
{ "vanir_signatures": [ { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@367e1e3399dbc56fc669740c4ab60e35da632b0e", "target": { "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "256443715818587822780296484808940952665", "160976244121854747397688553729659066974", "316272604723834016431761734959425598175", "338173366544413207653675577746035297724" ] }, "deprecated": false, "id": "CVE-2022-48949-152ee34e", "signature_type": "Line", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@51fd5ede7ed42f272682a0c33d6f0767b3484a3d", "target": { "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "256443715818587822780296484808940952665", "160976244121854747397688553729659066974", "316272604723834016431761734959425598175", "338173366544413207653675577746035297724" ] }, "deprecated": false, "id": "CVE-2022-48949-173face0", "signature_type": "Line", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f2479c3daaabccbac6c343a737615d0c595c6dc4", "target": { "function": "igb_vf_reset_msg", "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "length": 734.0, "function_hash": "136967172085530636276650094611309397589" }, "deprecated": false, "id": "CVE-2022-48949-25b3b47c", "signature_type": "Function", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c383c7c35c7bc15e07a04eefa060a8a80cbeae29", "target": { "function": "igb_vf_reset_msg", "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "length": 734.0, "function_hash": "136967172085530636276650094611309397589" }, "deprecated": false, "id": "CVE-2022-48949-34e0a4ce", "signature_type": "Function", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@367e1e3399dbc56fc669740c4ab60e35da632b0e", "target": { "function": "igb_vf_reset_msg", "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "length": 734.0, "function_hash": "136967172085530636276650094611309397589" }, "deprecated": false, "id": "CVE-2022-48949-4c54462d", "signature_type": "Function", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ef1d739dd1f362aec081278ff92f943c31eb177a", "target": { "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "256443715818587822780296484808940952665", "160976244121854747397688553729659066974", "316272604723834016431761734959425598175", "338173366544413207653675577746035297724" ] }, "deprecated": false, "id": "CVE-2022-48949-4ee4698a", "signature_type": "Line", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c581439a977545d61849a72e8ed631cfc8a2a3c1", "target": { "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "256443715818587822780296484808940952665", "160976244121854747397688553729659066974", "316272604723834016431761734959425598175", "338173366544413207653675577746035297724" ] }, "deprecated": false, "id": "CVE-2022-48949-529f73a1", "signature_type": "Line", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c581439a977545d61849a72e8ed631cfc8a2a3c1", "target": { "function": "igb_vf_reset_msg", "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "length": 734.0, "function_hash": "136967172085530636276650094611309397589" }, "deprecated": false, "id": "CVE-2022-48949-76979b89", "signature_type": "Function", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a6629659af3f5c6a91e3914ea62554c975ab77f4", "target": { "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "256443715818587822780296484808940952665", "160976244121854747397688553729659066974", "316272604723834016431761734959425598175", "338173366544413207653675577746035297724" ] }, "deprecated": false, "id": "CVE-2022-48949-7c8f9278", "signature_type": "Line", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c383c7c35c7bc15e07a04eefa060a8a80cbeae29", "target": { "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "256443715818587822780296484808940952665", "160976244121854747397688553729659066974", "316272604723834016431761734959425598175", "338173366544413207653675577746035297724" ] }, "deprecated": false, "id": "CVE-2022-48949-bb5ad7a7", "signature_type": "Line", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de5dc44370fbd6b46bd7f1a1e00369be54a041c8", "target": { "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "256443715818587822780296484808940952665", "160976244121854747397688553729659066974", "316272604723834016431761734959425598175", "338173366544413207653675577746035297724" ] }, "deprecated": false, "id": "CVE-2022-48949-d6aff224", "signature_type": "Line", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@51fd5ede7ed42f272682a0c33d6f0767b3484a3d", "target": { "function": "igb_vf_reset_msg", "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "length": 734.0, "function_hash": "136967172085530636276650094611309397589" }, "deprecated": false, "id": "CVE-2022-48949-d6c0a509", "signature_type": "Function", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de5dc44370fbd6b46bd7f1a1e00369be54a041c8", "target": { "function": "igb_vf_reset_msg", "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "length": 734.0, "function_hash": "136967172085530636276650094611309397589" }, "deprecated": false, "id": "CVE-2022-48949-da0d94b3", "signature_type": "Function", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f2479c3daaabccbac6c343a737615d0c595c6dc4", "target": { "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "256443715818587822780296484808940952665", "160976244121854747397688553729659066974", "316272604723834016431761734959425598175", "338173366544413207653675577746035297724" ] }, "deprecated": false, "id": "CVE-2022-48949-e84706d0", "signature_type": "Line", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a6629659af3f5c6a91e3914ea62554c975ab77f4", "target": { "function": "igb_vf_reset_msg", "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "length": 734.0, "function_hash": "136967172085530636276650094611309397589" }, "deprecated": false, "id": "CVE-2022-48949-f4e23bdd", "signature_type": "Function", "signature_version": "v1" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ef1d739dd1f362aec081278ff92f943c31eb177a", "target": { "function": "igb_vf_reset_msg", "file": "drivers/net/ethernet/intel/igb/igb_main.c" }, "digest": { "length": 734.0, "function_hash": "136967172085530636276650094611309397589" }, "deprecated": false, "id": "CVE-2022-48949-f9b9a3d3", "signature_type": "Function", "signature_version": "v1" } ] }