CVE-2022-49208

MEDIUM

Linux Kernel 5.14-5.14, 5.15-5.15.33, 5.16-5.16.19, 5.17-5.17.2 - Integer Underflow in RDMA/irdma CEQ Initialization

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Prevent some integer underflows My static checker complains that: drivers/infiniband/hw/irdma/ctrl.c:3605 irdma_sc_ceq_init() warn: can subtract underflow 'info->dev->hmc_fpm_misc.max_ceqs'? It appears that "info->dev->hmc_fpm_misc.max_ceqs" comes from the firmware in irdma_sc_parse_fpm_query_buf() so, yes, there is a chance that it could be zero. Even if we trust the firmware, it's easy enough to change the condition just as a hardenning measure.

Scores

CVSS v3 5.5
EPSS 0.0025
EPSS Percentile 15.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-191
Status published
Products (14)
linux/Kernel 5.14.0 - 5.15.33linux
linux/Kernel 5.16.0 - 5.16.19linux
linux/Kernel 5.17.0 - 5.17.2linux
Linux/Linux < 5.14
Linux/Linux 3f49d684256963d3f27dfb9d9ff228e2255be78d - 6f6dbb819dfc1a35bcb8b709b5c83a3ea8beff75
Linux/Linux 3f49d684256963d3f27dfb9d9ff228e2255be78d - 7340c3675d7ac946f4019b84cd7c64ed542dfe4c
Linux/Linux 3f49d684256963d3f27dfb9d9ff228e2255be78d - d52dab6e03550f9c97121b0c11c0a3ed78ee76a4
Linux/Linux 3f49d684256963d3f27dfb9d9ff228e2255be78d - f21056f15bbeacab7b4b87af232f5599d1f2bff1
Linux/Linux 5.14
Linux/Linux 5.15.33 - 5.15.*
... and 4 more
Published Feb 26, 2025
Tracked Since Feb 18, 2026