CVE-2022-2964: Buffer Overflow
A flaw was found in the Linux kernel’s driver for the ASIX AX88179178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.
Other sources
Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by multiple out-of-bounds reads and possible out-of-bounds writes flaw in the driver for the ASIX AX88179178A-based USB 2.0/3.0 Gigabit Ethernet Devices. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
— IBM
The linux kernels driver for the "ASIX AX88179178A based USB 2.0/3.0 Gigabit Ethernet Devices" contains multiple out-of-bounds reads and possible writes in the ax88179rxfixup() function.
References:
https://www.spinics.net/lists/stable/msg536418.html
Upstream commit: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=57bc3d3ae8c14df3ceb4e17d26ddf9eeab304581
— Red Hat
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2023:0400
- RHSA-2023:0399
- RHSA-2023:0404
- RHSA-2023:0114
- RHSA-2023:0101
- RHSA-2023:0123
- RHSA-2023:0856
- RHSA-2023:0858
- RHSA-2023:0395
- RHSA-2023:0392
- RHSA-2023:0396
- RHSA-2023:0531
- RHSA-2023:0496
- RHSA-2023:0499
- RHSA-2023:1130
- RHSA-2023:1192
- RHSA-2023:0334
- RHSA-2023:0300
- RHSA-2023:0348
- RHSA-2023:0512
- RHSA-2023:0526
- RHSA-2023:0536
- IBM-7183851
Frequently Asked Questions
What is the severity of CVE-2022-2964?
CVE-2022-2964 has been classified with a medium severity due to multiple out-of-bounds reads and possible writes that can impact system stability.
How do I fix CVE-2022-2964?
To fix CVE-2022-2964, upgrade to the appropriate kernel versions specified for your distribution, such as kernel-rt 3.10.0-1160.83.1.el7 or later.
Which systems are affected by CVE-2022-2964?
CVE-2022-2964 affects Linux kernels ranging from 3.10.0 to 5.14.0, impacting systems that utilize ASIX AX88179_178A-based USB Ethernet devices.
Is CVE-2022-2964 related to specific Linux distributions?
Yes, CVE-2022-2964 predominantly affects Red Hat Enterprise Linux versions 7, 8, and 9, among other Linux distributions.
What are the potential risks of CVE-2022-2964 if not mitigated?
If not mitigated, CVE-2022-2964 could lead to unauthorized access, data corruption, or service disruptions due to out-of-bounds memory operations.