imPC@ndo IT

Tracker / CVE-2022-49048

CVE-2022-49048

High 7.5

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix panic when forwarding a pkt with no in6 dev kongweibin reported a kernel panic in ip6_forward() when input interface has no in6 dev associated. The following tc commands were used to reproduce this panic: tc qdisc del dev vxlan100 root tc qdisc add dev vxlan100 root netem corrupt 5%

Affected products and versions

linux linux_kernel
linux linux_kernel · 4.19.199 → 4.19.239
linux linux_kernel · 5.10.54 → 5.10.112
linux linux_kernel · 5.13.6 → 5.14
linux linux_kernel · 5.14.1 → 5.15.35
linux linux_kernel · 5.16 → 5.17.4
linux linux_kernel · 5.4.136 → 5.4.190

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References