CVE-2022-49642

Source
https://cve.org/CVERecord?id=CVE-2022-49642
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49642.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49642
Downstream
Related
Published
2025-02-26T02:23:49.154Z
Modified
2026-03-12T03:25:33.910308Z
Summary
net: stmmac: dwc-qos: Disable split header for Tegra194
Details

In the Linux kernel, the following vulnerability has been resolved:

net: stmmac: dwc-qos: Disable split header for Tegra194

There is a long-standing issue with the Synopsys DWC Ethernet driver for Tegra194 where random system crashes have been observed [0]. The problem occurs when the split header feature is enabled in the stmmac driver. In the bad case, a larger than expected buffer length is received and causes the calculation of the total buffer length to overflow. This results in a very large buffer length that causes the kernel to crash. Why this larger buffer length is received is not clear, however, the feedback from the NVIDIA design team is that the split header feature is not supported for Tegra194. Therefore, disable split header support for Tegra194 to prevent these random crashes from occurring.

[0] https://lore.kernel.org/linux-tegra/b0b17697-f23e-8fa5-3757-604a86f3a095@nvidia.com/

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49642.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
67afd6d1cfdf0d0461fe3c4c922447f3e9b1c6ee
Fixed
2968830c9b47ce093237483c6207c61065712386
Fixed
9cc8edc571b871d974b3289868553f9ce544aba6
Fixed
d5c315a787652c35045044877a249f7d5c8a4104
Fixed
cfa4caf3e881ad6dd366c903c34f1c7f21b857ab
Fixed
029c1c2059e9c4b38f97a06204cdecd10cfbeb8a

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49642.json"