
Cloud Vulnerability DB
A community-led vulnerabilities database
A flaw was discovered in the Linux kernel's driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability (CVE-2022-2964) was identified in kernel versions prior to 5.17 and contains multiple out-of-bounds reads and possible out-of-bounds writes in the ax88179_rx_fixup() function. The issue was discovered by Jann Horn and was fixed in kernel version 5.17 (Kernel Fix).
The vulnerability exists in the ax88179_rx_fixup() function within the Linux kernel's driver for ASIX AX88179_178A USB Ethernet devices. The issue manifests as multiple out-of-bounds read operations and potential out-of-bounds write operations. The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (High), with the following vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NetApp Security).
Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or a denial of service (DoS) condition. A local attacker with physical access could potentially exploit this vulnerability by plugging in a specially crafted USB device to cause system crashes or possibly execute arbitrary code (Ubuntu Security).
The vulnerability requires local access and physical access to the target system. An attacker would need to connect a specially crafted USB device to exploit the vulnerability. The attack complexity is considered low, requiring minimal specialized access conditions or extenuating circumstances (NetApp Security).
The primary mitigation is to update to Linux kernel version 5.17 or later, which contains the fix for this vulnerability. Multiple Linux distributions have released security updates to address this issue, including Red Hat Enterprise Linux, Ubuntu, and Debian. The fix was implemented through a patch that corrects the out-of-bounds operations in the ax88179_rx_fixup() function (Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."