CVE-2022-48744·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Avoid field-overflowing memcpy() In preparation for FORTIFY_SOURCE performing compile-time and run-time field bounds checking for memcpy(), memmove(), and memset(), avoid intentionally writing across neighboring fields. Use flexible arrays instead of zero-element arrays (which look like they are always overflowing) and split the cross-field memcpy() into two halves that can be appropriately bounds-checked by the compiler. We were doing: #define ETH_HLEN 14 #define VLAN_HLEN 4 ... #define MLX5E_XDP_MIN_INLINE (ETH_HLEN + VLAN_HLEN) ... struct mlx5e_tx_wqe *wqe = mlx5_wq_cyc_get_wqe(wq, pi); ... struct mlx5_wqe_eth_seg *eseg = &wqe->eth; struct mlx5_wqe_data_seg *dseg = wqe->data; ... memcpy(eseg->inline_hdr.start, xdptxd->data, MLX5E_XDP_MIN_INLINE); target is wqe->eth.inline_hdr.start (which the compiler sees as being 2 bytes in size), but copying 18, intending to write across start (really vlan_tci, 2 bytes). The remaining 16 bytes get written into wqe->data[0], covering byte_count (4 bytes), lkey (4 bytes), and addr (8 bytes). struct mlx5e_tx_wqe { struct mlx5_wqe_ctrl_seg ctrl; /* 0 16 */ struct mlx5_wqe_eth_seg eth; /* 16 16 */ struct mlx5_wqe_data_seg data[]; /* 32 0 */ /* size: 32, cachelines: 1, members: 3 */ /* last cacheline: 32 bytes */ }; struct mlx5_wqe_eth_seg { u8 swp_outer_l4_offset; /* 0 1 */ u8 swp_outer_l3_offset; /* 1 1 */ u8 swp_inner_l4_offset; /* 2 1 */ u8 swp_inner_l3_offset; /* 3 1 */ u8 cs_flags; /* 4 1 */ u8 swp_flags; /* 5 1 */ __be16 mss; /* 6 2 */ __be32 flow_table_metadata; /* 8 4 */ union { struct { __be16 sz; /* 12 2 */ u8 start[2]; /* 14 2 */ } inline_hdr; /* 12 4 */ struct { __be16 type; /* 12 2 */ __be16 vlan_tci; /* 14 2 */ } insert; /* 12 4 */ __be32 trailer; /* 12 4 */ }; /* 12 4 */ /* size: 16, cachelines: 1, members: 9 */ /* last cacheline: 16 bytes */ }; struct mlx5_wqe_data_seg { __be32 byte_count; /* 0 4 */ __be32 lkey; /* 4 4 */ __be64 addr; /* 8 8 */ /* size: 16, cachelines: 1, members: 3 */ /* last cacheline: 16 bytes */ }; So, split the memcpy() so the compiler can reason about the buffer sizes. "pahole" shows no size nor member offset changes to struct mlx5e_tx_wqe nor struct mlx5e_umr_wqe. "objdump -d" shows no meaningful object code changes (i.e. only source line number induced differences and optimizations).
- Severity
- high
- Software
- Kernel
- Fixed in
- 5.16.6
- Published
- 2024-06-20
Affected versions
From: 5.11
Until: 5.16.6
Fixed in: 5.16.6
How to fix this CVE
Update the Linux kernel to version 5.16.6 or later to resolve a memory bounds-checking vulnerability in the MLX5 Ethernet driver. This patch corrects unsafe memcpy() operations that could write beyond intended buffer boundaries during XDP packet transmission. Systems running kernel versions 5.11 through 5.16.5 should prioritize this update to prevent potential kernel memory corruption.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check your kernel version: uname -r
- Verify if affected: if kernel version is between 5.11 and 5.16.5, your system is vulnerable
- Confirm MLX5 driver is loaded: lsmod | grep mlx5
- After patching, verify: uname -r should show 5.16.6 or later
FAQ
What is CVE-2022-48744?
CVE-2022-48744 is a kernel memory safety vulnerability in the MLX5 Ethernet driver where memcpy() operations could overflow into adjacent data structure fields during XDP packet processing, potentially corrupting kernel memory.
Is CVE-2022-48744 being actively exploited?
No, this vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, and no public exploits are available.
What versions of Kernel are affected by CVE-2022-48744?
Linux kernel versions 5.11 through 5.16.5 are vulnerable. Kernel 5.16.6 and later contain the fix.
How do I check if my server is vulnerable to CVE-2022-48744?
Run `uname -r` to display your kernel version. If it shows 5.11.x through 5.16.5, you are vulnerable. Additionally, verify MLX5 driver presence with `lsmod | grep mlx5`.
Does Defensia detect CVE-2022-48744?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2022-48744 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/49bcbe531f79fc35bb10020f7695f9f01e4f0ca8
- https://git.kernel.org/stable/c/8fbdf8c8b8ab82beab882175157650452c46493e
- https://git.kernel.org/stable/c/ad5185735f7dab342fdd0dd41044da4c9ccfef67
- https://git.kernel.org/stable/c/8fbdf8c8b8ab82beab882175157650452c46493e
- https://git.kernel.org/stable/c/ad5185735f7dab342fdd0dd41044da4c9ccfef67
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2022-48744. Free for 1 server.
Get started free