5.5

CVE-2022-49019

net: ethernet: nixge: fix NULL dereference

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: nixge: fix NULL dereference

In function nixge_hw_dma_bd_release() dereference of NULL pointer
priv->rx_bd_v is possible for the case of its allocation failure in
nixge_hw_dma_bd_init().

Move for() loop with priv->rx_bd_v dereference under the check for
its validity.

Found by Linux Verification Center (linuxtesting.org) with SVACE.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.17 < 5.4.226
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.158
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.82
Linux ≫ Linux Kernel Version >= 5.16 < 6.0.12
Linux ≫ Linux Kernel Version 6.1 Update rc1
Linux ≫ Linux Kernel Version 6.1 Update rc2
Linux ≫ Linux Kernel Version 6.1 Update rc3
Linux ≫ Linux Kernel Version 6.1 Update rc4
Linux ≫ Linux Kernel Version 6.1 Update rc5
Linux ≫ Linux Kernel Version 6.1 Update rc6
Linux ≫ Linux Kernel Version 6.1 Update rc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.146
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://git.kernel.org/stable/c/45752af0247589e6d3dede577415bfe117b4392c
Patch
https://git.kernel.org/stable/c/80e82f7b440b65cf131dce10f487dc73a7046e6b
Patch
https://git.kernel.org/stable/c/910c0264b64ef2dad8887714a7c56c93e39a0ed3
Patch
https://git.kernel.org/stable/c/9256db4e45e8b497b0e993cc3ed4ad08eb2389b6
Patch
https://git.kernel.org/stable/c/9c584d6d9cfb935dce8fc81a4c26debac0a3049b
Patch