CVE-2022-3594: Linux Kernel BPF r8152.c intr_callback logging of excessive data
A vulnerability was found in Linux Kernel in intrcallback in drivers/net/usb/r8152.c. The manipulation leads to logging of excessive data. The attack can be launched remotely.
https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=93e2be344a7db169b7119de21ac1bf253b8c6907
Other sources
A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function intrcallback of the file drivers/net/usb/r8152.c of the component BPF. The manipulation leads to logging of excessive data. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211363.
Linux Kernel is vulnerable to a denial of service, caused by an error in the function intrcallback of the file drivers/net/usb/r8152.c of the component BPF. A remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3594?
CVE-2022-3594 is classified as a medium severity vulnerability that leads to excessive data logging.
How do I fix CVE-2022-3594?
To fix CVE-2022-3594, update the Linux kernel to version 6.1 or apply the recommended patches from your distribution.
Which software is affected by CVE-2022-3594?
CVE-2022-3594 affects various versions of the Linux Kernel, specifically prior to 6.1, and components of IBM Security Verify Governance.
Can CVE-2022-3594 be exploited remotely?
Yes, CVE-2022-3594 can be exploited remotely, allowing attackers to potentially manipulate data logging processes.
What type of vulnerability is CVE-2022-3594?
CVE-2022-3594 is a vulnerability found in the Linux Kernel concerning data logging in the USB driver.