CVE-2022-48999
21.10.2024, 20:15
In the Linux kernel, the following vulnerability has been resolved: ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference Gwangun Jung reported a slab-out-of-bounds access in fib_nh_match: fib_nh_match+0xf98/0x1130 linux-6.0-rc7/net/ipv4/fib_semantics.c:961 fib_table_delete+0x5f3/0xa40 linux-6.0-rc7/net/ipv4/fib_trie.c:1753 inet_rtm_delroute+0x2b3/0x380 linux-6.0-rc7/net/ipv4/fib_frontend.c:874 Separate nexthop objects are mutually exclusive with the legacy multipath spec. Fix fib_nh_match to return if the config for the to be deleted route contains a multipath spec while the fib_info is using a nexthop object.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 5.3 ≤ 𝑥 < 5.4.226 |
linux | linux_kernel | 5.5 ≤ 𝑥 < 5.10.158 |
linux | linux_kernel | 5.11 ≤ 𝑥 < 5.15.82 |
linux | linux_kernel | 5.16 ≤ 𝑥 < 6.0.12 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration
References