CVE-2022-49084

MEDIUM EPSS 14.1%
Published Feb 26, 20251y ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Feb 26, 2025 1y ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: qede: confirm skb is allocated before using qede_build_skb() assumes build_skb() always works and goes straight to skb_reserve(). However, build_skb() can fail under memory pressure. This results in a kernel panic because the skb to reserve is NULL. Add a check in case build_skb() failed to allocate and return NULL. The NULL return is handled correctly in callers to qede_build_skb().

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
14.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 7

VendorProductVersionRange
linuxlinux_kernel*≥4.18  –  <4.19.238
linuxlinux_kernel*≥4.20  –  <5.4.189
linuxlinux_kernel*≥5.5  –  <5.10.111
linuxlinux_kernel*≥5.11  –  <5.15.34
linuxlinux_kernel*≥5.16  –  <5.16.20
linuxlinux_kernel*≥5.17  –  <5.17.3
linuxlinux_kernel5.18any

References 7

  • git.kernel.org https://git.kernel.org/stable/c/034a92c6a81048128fc7b18d278d52438a13902a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4e910dbe36508654a896d5735b318c0b88172570
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8928239e5e2e460d95b8a0b89f61671625e7ece0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9648adb1b3ece55c657d3a4f52bfee663b710dfe
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b2d6b3db9d1cf80908964036dbe1c52a86b1afb1
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c9bdce2359b5f4986eb38d1e81865b3586cc20d2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e1fd0c42acfa22bb34d2ab6a111484f466ab8093
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/034a92c6a81048128fc7b18d278d52438a13902a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4e910dbe36508654a896d5735b318c0b88172570
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8928239e5e2e460d95b8a0b89f61671625e7ece0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9648adb1b3ece55c657d3a4f52bfee663b710dfe
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b2d6b3db9d1cf80908964036dbe1c52a86b1afb1
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c9bdce2359b5f4986eb38d1e81865b3586cc20d2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e1fd0c42acfa22bb34d2ab6a111484f466ab8093
    Patch