In the Linux kernel, the following vulnerability has been resolved:
igb: Initialize mailbox message for VF reset
When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.
[
{
"id": "CVE-2022-48949-152ee34e",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@367e1e3399dbc56fc669740c4ab60e35da632b0e",
"signature_version": "v1"
},
{
"id": "CVE-2022-48949-173face0",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@51fd5ede7ed42f272682a0c33d6f0767b3484a3d",
"signature_version": "v1"
},
{
"id": "CVE-2022-48949-25b3b47c",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f2479c3daaabccbac6c343a737615d0c595c6dc4",
"signature_version": "v1"
},
{
"id": "CVE-2022-48949-34e0a4ce",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c383c7c35c7bc15e07a04eefa060a8a80cbeae29",
"signature_version": "v1"
},
{
"id": "CVE-2022-48949-4c54462d",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@367e1e3399dbc56fc669740c4ab60e35da632b0e",
"signature_version": "v1"
},
{
"id": "CVE-2022-48949-529f73a1",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c581439a977545d61849a72e8ed631cfc8a2a3c1",
"signature_version": "v1"
},
{
"id": "CVE-2022-48949-76979b89",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c581439a977545d61849a72e8ed631cfc8a2a3c1",
"signature_version": "v1"
},
{
"id": "CVE-2022-48949-bb5ad7a7",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c383c7c35c7bc15e07a04eefa060a8a80cbeae29",
"signature_version": "v1"
},
{
"id": "CVE-2022-48949-d6aff224",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de5dc44370fbd6b46bd7f1a1e00369be54a041c8",
"signature_version": "v1"
},
{
"id": "CVE-2022-48949-d6c0a509",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@51fd5ede7ed42f272682a0c33d6f0767b3484a3d",
"signature_version": "v1"
},
{
"id": "CVE-2022-48949-da0d94b3",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c",
"function": "igb_vf_reset_msg"
},
"digest": {
"function_hash": "136967172085530636276650094611309397589",
"length": 734.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de5dc44370fbd6b46bd7f1a1e00369be54a041c8",
"signature_version": "v1"
},
{
"id": "CVE-2022-48949-e84706d0",
"target": {
"file": "drivers/net/ethernet/intel/igb/igb_main.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"256443715818587822780296484808940952665",
"160976244121854747397688553729659066974",
"316272604723834016431761734959425598175",
"338173366544413207653675577746035297724"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f2479c3daaabccbac6c343a737615d0c595c6dc4",
"signature_version": "v1"
}
]