CVE-2022-48949

MEDIUM

Linux Kernel 4.0-6.1.1 Information Disclosure via Uninitialized Mailbox Message

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: igb: Initialize mailbox message for VF reset When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.

Scores

CVSS v3 5.5
EPSS 0.0025
EPSS Percentile 16.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-908
Status published
Products (28)
linux/Kernel 4.0.0 - 4.14.303linux
linux/Kernel 4.15.0 - 4.19.270linux
linux/Kernel 4.20.0 - 5.4.229linux
linux/Kernel 5.11.0 - 5.15.85linux
linux/Kernel 5.16.0 - 6.0.15linux
linux/Kernel 5.5.0 - 5.10.161linux
linux/Kernel 6.1.0 - 6.1.1linux
Linux/Linux < 4.0
Linux/Linux 4.0
Linux/Linux 4.14.303 - 4.14.*
... and 18 more
Published Oct 21, 2024
Tracked Since Feb 18, 2026