U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-49654

Change History

New CVE Received from kernel.org 2/26/2025 2:01:40 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

net: dsa: qca8k: reset cpu port on MTU change

It was discovered that the Documentation lacks of a fundamental detail
on how to correctly change the MAX_FRAME_SIZE of the switch.

In fact if the MAX_FRAME_SIZE is changed while the cpu port is on, the
switch panics and cease to send any packet. This cause the mgmt ethernet
system to not receive any packet (the slow fallback still works) and
makes the device not reachable. To recover from this a switch reset is
required.

To correctly handle this, turn off the cpu ports before changing the
MAX_FRAME_SIZE and turn on again after the value is applied.
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/188c798f3c2554fa0d7147e9b97baf144b817019
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/1993f5a06736ada59dd54b50dc96755a38796ee5
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/386228c694bf1e7a7688e44412cb33500b0ac585