U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-48999

Change History

New CVE Received from kernel.org 10/21/2024 4:15:11 PM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference

Gwangun Jung reported a slab-out-of-bounds access in fib_nh_match:
    fib_nh_match+0xf98/0x1130 linux-6.0-rc7/net/ipv4/fib_semantics.c:961
    fib_table_delete+0x5f3/0xa40 linux-6.0-rc7/net/ipv4/fib_trie.c:1753
    inet_rtm_delroute+0x2b3/0x380 linux-6.0-rc7/net/ipv4/fib_frontend.c:874

Separate nexthop objects are mutually exclusive with the legacy
multipath spec. Fix fib_nh_match to return if the config for the
to be deleted route contains a multipath spec while the fib_info
is using a nexthop object.
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/0b5394229ebae09afc07aabccb5ffd705ffd250e [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/25174d91e4a32a24204060d283bd5fa6d0ddf133 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/61b91eb33a69c3be11b259c5ea484505cd79f883 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/bb20a2ae241be846bc3c11ea4b3a3c69e41d51f2 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/cc3cd130ecfb8b0ae52e235e487bae3f16a24a32 [No types assigned]