CVE-2022-48711 (GCVE-0-2022-48711)
Vulnerability from cvelistv5
Published
2024-06-20 11:13
Modified
2026-08-05 08:51
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: tipc: improve size validations for received domain records The function tipc_mon_rcv() allows a node to receive and process domain_record structs from peer nodes to track their views of the network topology. This patch verifies that the number of members in a received domain record does not exceed the limit defined by MAX_MON_DOMAIN, something that may otherwise lead to a stack overflow. tipc_mon_rcv() is called from the function tipc_link_proto_rcv(), where we are reading a 32 bit message data length field into a uint16. To avert any risk of bit overflow, we add an extra sanity check for this in that function. We cannot see that happen with the current code, but future designers being unaware of this risk, may introduce it by allowing delivery of very large (> 64k) sk buffers from the bearer layer. This potential problem was identified by Eric Dumazet. This fixes CVE-2022-0435
Impacted products
Vendor Product Version
Linux Linux Version: 35c55c9877f8de0ab129fa1a309271d0ecc868b9
Version: 35c55c9877f8de0ab129fa1a309271d0ecc868b9
Version: 35c55c9877f8de0ab129fa1a309271d0ecc868b9
Version: 35c55c9877f8de0ab129fa1a309271d0ecc868b9
Version: 35c55c9877f8de0ab129fa1a309271d0ecc868b9
Version: 35c55c9877f8de0ab129fa1a309271d0ecc868b9
Version: 35c55c9877f8de0ab129fa1a309271d0ecc868b9
Version: 35c55c9877f8de0ab129fa1a309271d0ecc868b9
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "LOW",
              "baseScore": 5.3,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "LOW",
              "integrityImpact": "LOW",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2022-48711",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-06-20T13:31:43.909633Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "description": "CWE-noinfo Not enough information",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-10-30T15:55:17.144Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T15:17:55.714Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/175db196e45d6f0e6047eccd09c8ba55465eb131"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/fde4ddeadd099bf9fbb9ccbee8e1b5c20d530a2d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/f1af11edd08dd8376f7a84487cbb0ea8203e3a1d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/d692e3406e052dbf9f6d9da0cba36cb763272529"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/3c7e5943553594f68bbc070683db6bb6f6e9e78e"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/1f1788616157b0222b0c2153828b475d95e374a7"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/59ff7514f8c56f166aadca49bcecfa028e0ad50f"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/9aa422ad326634b76309e8ff342c246800621216"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/tipc/link.c",
            "net/tipc/monitor.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "175db196e45d6f0e6047eccd09c8ba55465eb131",
              "status": "affected",
              "version": "35c55c9877f8de0ab129fa1a309271d0ecc868b9",
              "versionType": "git"
            },
            {
              "lessThan": "fde4ddeadd099bf9fbb9ccbee8e1b5c20d530a2d",
              "status": "affected",
              "version": "35c55c9877f8de0ab129fa1a309271d0ecc868b9",
              "versionType": "git"
            },
            {
              "lessThan": "f1af11edd08dd8376f7a84487cbb0ea8203e3a1d",
              "status": "affected",
              "version": "35c55c9877f8de0ab129fa1a309271d0ecc868b9",
              "versionType": "git"
            },
            {
              "lessThan": "d692e3406e052dbf9f6d9da0cba36cb763272529",
              "status": "affected",
              "version": "35c55c9877f8de0ab129fa1a309271d0ecc868b9",
              "versionType": "git"
            },
            {
              "lessThan": "3c7e5943553594f68bbc070683db6bb6f6e9e78e",
              "status": "affected",
              "version": "35c55c9877f8de0ab129fa1a309271d0ecc868b9",
              "versionType": "git"
            },
            {
              "lessThan": "1f1788616157b0222b0c2153828b475d95e374a7",
              "status": "affected",
              "version": "35c55c9877f8de0ab129fa1a309271d0ecc868b9",
              "versionType": "git"
            },
            {
              "lessThan": "59ff7514f8c56f166aadca49bcecfa028e0ad50f",
              "status": "affected",
              "version": "35c55c9877f8de0ab129fa1a309271d0ecc868b9",
              "versionType": "git"
            },
            {
              "lessThan": "9aa422ad326634b76309e8ff342c246800621216",
              "status": "affected",
              "version": "35c55c9877f8de0ab129fa1a309271d0ecc868b9",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/tipc/link.c",
            "net/tipc/monitor.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.8"
            },
            {
              "lessThan": "4.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.9.*",
              "status": "unaffected",
              "version": "4.9.301",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.14.*",
              "status": "unaffected",
              "version": "4.14.266",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.229",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.179",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.100",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.23",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.16.*",
              "status": "unaffected",
              "version": "5.16.9",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "5.17",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.9.301",
                  "versionStartIncluding": "4.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.14.266",
                  "versionStartIncluding": "4.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.229",
                  "versionStartIncluding": "4.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.179",
                  "versionStartIncluding": "4.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.100",
                  "versionStartIncluding": "4.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.23",
                  "versionStartIncluding": "4.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.16.9",
                  "versionStartIncluding": "4.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.17",
                  "versionStartIncluding": "4.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: improve size validations for received domain records\n\nThe function tipc_mon_rcv() allows a node to receive and process\ndomain_record structs from peer nodes to track their views of the\nnetwork topology.\n\nThis patch verifies that the number of members in a received domain\nrecord does not exceed the limit defined by MAX_MON_DOMAIN, something\nthat may otherwise lead to a stack overflow.\n\ntipc_mon_rcv() is called from the function tipc_link_proto_rcv(), where\nwe are reading a 32 bit message data length field into a uint16.  To\navert any risk of bit overflow, we add an extra sanity check for this in\nthat function.  We cannot see that happen with the current code, but\nfuture designers being unaware of this risk, may introduce it by\nallowing delivery of very large (\u003e 64k) sk buffers from the bearer\nlayer.  This potential problem was identified by Eric Dumazet.\n\nThis fixes CVE-2022-0435"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The bug is reached by processing received TIPC LINK_PROTOCOL/STATE_MSG packets on an enabled bearer (Ethernet, InfiniBand, or UDP/6118) via tipc_rcv \u2192 tipc_link_proto_rcv \u2192 tipc_mon_rcv, so a remote peer can trigger it over the network.\nAC:L - The attacker fully controls discovery, link establishment, and the two crafted domain records that trigger the overflow; researchers describe exploitation as trivial and reliable with no race or victim-state dependency.\nPR:N - Default TIPC has no authentication for peer join (crypto is optional); an unauthenticated attacker who can reach the bearer and match the cluster net_id (default 4711) can establish a link and send the malicious STATE_MSG.\nUI:N - Exploitation requires only sending TIPC protocol packets to a system with an active bearer; no victim user action is needed.\nS:U - Successful exploitation compromises the local kernel on the same host; it does not cross a VM, IOMMU, or other separate security authority boundary.\nC:H - Attacker-controlled stack overflow can hijack kernel control flow and yield arbitrary kernel read primitives, enabling full confidentiality loss.\nI:H - The overflow overwrites stack contents including saved registers and the return address with attacker-controlled payload, enabling control-flow hijacking and arbitrary code execution in kernel context.\nA:H - Triggering the overflow causes kernel panic/oops (including under stack canary or FORTIFY_SOURCE), resulting in complete denial of service."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T08:51:52.646Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/175db196e45d6f0e6047eccd09c8ba55465eb131"
        },
        {
          "url": "https://git.kernel.org/stable/c/fde4ddeadd099bf9fbb9ccbee8e1b5c20d530a2d"
        },
        {
          "url": "https://git.kernel.org/stable/c/f1af11edd08dd8376f7a84487cbb0ea8203e3a1d"
        },
        {
          "url": "https://git.kernel.org/stable/c/d692e3406e052dbf9f6d9da0cba36cb763272529"
        },
        {
          "url": "https://git.kernel.org/stable/c/3c7e5943553594f68bbc070683db6bb6f6e9e78e"
        },
        {
          "url": "https://git.kernel.org/stable/c/1f1788616157b0222b0c2153828b475d95e374a7"
        },
        {
          "url": "https://git.kernel.org/stable/c/59ff7514f8c56f166aadca49bcecfa028e0ad50f"
        },
        {
          "url": "https://git.kernel.org/stable/c/9aa422ad326634b76309e8ff342c246800621216"
        }
      ],
      "title": "tipc: improve size validations for received domain records",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2022-48711",
    "datePublished": "2024-06-20T11:13:06.050Z",
    "dateReserved": "2024-06-20T11:09:39.049Z",
    "dateUpdated": "2026-08-05T08:51:52.646Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/175db196e45d6f0e6047eccd09c8ba55465eb131\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/fde4ddeadd099bf9fbb9ccbee8e1b5c20d530a2d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/f1af11edd08dd8376f7a84487cbb0ea8203e3a1d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/d692e3406e052dbf9f6d9da0cba36cb763272529\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/3c7e5943553594f68bbc070683db6bb6f6e9e78e\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/1f1788616157b0222b0c2153828b475d95e374a7\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/59ff7514f8c56f166aadca49bcecfa028e0ad50f\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/9aa422ad326634b76309e8ff342c246800621216\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-03T15:17:55.714Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 5.3, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L\", \"integrityImpact\": \"LOW\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"LOW\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"LOW\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2022-48711\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-06-20T13:31:43.909633Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"description\": \"CWE-noinfo Not enough information\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-06-20T13:31:49.461Z\"}}], \"cna\": {\"title\": \"tipc: improve size validations for received domain records\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 9.8, \"baseSeverity\": \"CRITICAL\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:N - The bug is reached by processing received TIPC LINK_PROTOCOL/STATE_MSG packets on an enabled bearer (Ethernet, InfiniBand, or UDP/6118) via tipc_rcv \\u2192 tipc_link_proto_rcv \\u2192 tipc_mon_rcv, so a remote peer can trigger it over the network.\\nAC:L - The attacker fully controls discovery, link establishment, and the two crafted domain records that trigger the overflow; researchers describe exploitation as trivial and reliable with no race or victim-state dependency.\\nPR:N - Default TIPC has no authentication for peer join (crypto is optional); an unauthenticated attacker who can reach the bearer and match the cluster net_id (default 4711) can establish a link and send the malicious STATE_MSG.\\nUI:N - Exploitation requires only sending TIPC protocol packets to a system with an active bearer; no victim user action is needed.\\nS:U - Successful exploitation compromises the local kernel on the same host; it does not cross a VM, IOMMU, or other separate security authority boundary.\\nC:H - Attacker-controlled stack overflow can hijack kernel control flow and yield arbitrary kernel read primitives, enabling full confidentiality loss.\\nI:H - The overflow overwrites stack contents including saved registers and the return address with attacker-controlled payload, enabling control-flow hijacking and arbitrary code execution in kernel context.\\nA:H - Triggering the overflow causes kernel panic/oops (including under stack canary or FORTIFY_SOURCE), resulting in complete denial of service.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"35c55c9877f8de0ab129fa1a309271d0ecc868b9\", \"lessThan\": \"175db196e45d6f0e6047eccd09c8ba55465eb131\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"35c55c9877f8de0ab129fa1a309271d0ecc868b9\", \"lessThan\": \"fde4ddeadd099bf9fbb9ccbee8e1b5c20d530a2d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"35c55c9877f8de0ab129fa1a309271d0ecc868b9\", \"lessThan\": \"f1af11edd08dd8376f7a84487cbb0ea8203e3a1d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"35c55c9877f8de0ab129fa1a309271d0ecc868b9\", \"lessThan\": \"d692e3406e052dbf9f6d9da0cba36cb763272529\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"35c55c9877f8de0ab129fa1a309271d0ecc868b9\", \"lessThan\": \"3c7e5943553594f68bbc070683db6bb6f6e9e78e\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"35c55c9877f8de0ab129fa1a309271d0ecc868b9\", \"lessThan\": \"1f1788616157b0222b0c2153828b475d95e374a7\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"35c55c9877f8de0ab129fa1a309271d0ecc868b9\", \"lessThan\": \"59ff7514f8c56f166aadca49bcecfa028e0ad50f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"35c55c9877f8de0ab129fa1a309271d0ecc868b9\", \"lessThan\": \"9aa422ad326634b76309e8ff342c246800621216\", \"versionType\": \"git\"}], \"programFiles\": [\"net/tipc/link.c\", \"net/tipc/monitor.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.8\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.8\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"4.9.301\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"4.9.*\"}, {\"status\": \"unaffected\", \"version\": \"4.14.266\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"4.14.*\"}, {\"status\": \"unaffected\", \"version\": \"4.19.229\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"4.19.*\"}, {\"status\": \"unaffected\", \"version\": \"5.4.179\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.100\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.23\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"5.16.9\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.16.*\"}, {\"status\": \"unaffected\", \"version\": \"5.17\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"net/tipc/link.c\", \"net/tipc/monitor.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/175db196e45d6f0e6047eccd09c8ba55465eb131\"}, {\"url\": \"https://git.kernel.org/stable/c/fde4ddeadd099bf9fbb9ccbee8e1b5c20d530a2d\"}, {\"url\": \"https://git.kernel.org/stable/c/f1af11edd08dd8376f7a84487cbb0ea8203e3a1d\"}, {\"url\": \"https://git.kernel.org/stable/c/d692e3406e052dbf9f6d9da0cba36cb763272529\"}, {\"url\": \"https://git.kernel.org/stable/c/3c7e5943553594f68bbc070683db6bb6f6e9e78e\"}, {\"url\": \"https://git.kernel.org/stable/c/1f1788616157b0222b0c2153828b475d95e374a7\"}, {\"url\": \"https://git.kernel.org/stable/c/59ff7514f8c56f166aadca49bcecfa028e0ad50f\"}, {\"url\": \"https://git.kernel.org/stable/c/9aa422ad326634b76309e8ff342c246800621216\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ntipc: improve size validations for received domain records\\n\\nThe function tipc_mon_rcv() allows a node to receive and process\\ndomain_record structs from peer nodes to track their views of the\\nnetwork topology.\\n\\nThis patch verifies that the number of members in a received domain\\nrecord does not exceed the limit defined by MAX_MON_DOMAIN, something\\nthat may otherwise lead to a stack overflow.\\n\\ntipc_mon_rcv() is called from the function tipc_link_proto_rcv(), where\\nwe are reading a 32 bit message data length field into a uint16.  To\\navert any risk of bit overflow, we add an extra sanity check for this in\\nthat function.  We cannot see that happen with the current code, but\\nfuture designers being unaware of this risk, may introduce it by\\nallowing delivery of very large (\u003e 64k) sk buffers from the bearer\\nlayer.  This potential problem was identified by Eric Dumazet.\\n\\nThis fixes CVE-2022-0435\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.9.301\", \"versionStartIncluding\": \"4.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.14.266\", \"versionStartIncluding\": \"4.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.19.229\", \"versionStartIncluding\": \"4.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.179\", \"versionStartIncluding\": \"4.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.100\", \"versionStartIncluding\": \"4.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.23\", \"versionStartIncluding\": \"4.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.16.9\", \"versionStartIncluding\": \"4.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.17\", \"versionStartIncluding\": \"4.8\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T08:51:52.646Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2022-48711\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T08:51:52.646Z\", \"dateReserved\": \"2024-06-20T11:09:39.049Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-06-20T11:13:06.050Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…