Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2022-2964
Linux Kernel vulnerability analysis and mitigation

Overview

A flaw was discovered in the Linux kernel's driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability (CVE-2022-2964) was identified in kernel versions prior to 5.17 and contains multiple out-of-bounds reads and possible out-of-bounds writes in the ax88179_rx_fixup() function. The issue was discovered by Jann Horn and was fixed in kernel version 5.17 (Kernel Fix).

Technical details

The vulnerability exists in the ax88179_rx_fixup() function within the Linux kernel's driver for ASIX AX88179_178A USB Ethernet devices. The issue manifests as multiple out-of-bounds read operations and potential out-of-bounds write operations. The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (High), with the following vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NetApp Security).

Impact

Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or a denial of service (DoS) condition. A local attacker with physical access could potentially exploit this vulnerability by plugging in a specially crafted USB device to cause system crashes or possibly execute arbitrary code (Ubuntu Security).

Exploitability

The vulnerability requires local access and physical access to the target system. An attacker would need to connect a specially crafted USB device to exploit the vulnerability. The attack complexity is considered low, requiring minimal specialized access conditions or extenuating circumstances (NetApp Security).

Mitigation and workarounds

The primary mitigation is to update to Linux kernel version 5.17 or later, which contains the fix for this vulnerability. Multiple Linux distributions have released security updates to address this issue, including Red Hat Enterprise Linux, Ubuntu, and Debian. The fix was implemented through a patch that corrects the out-of-bounds operations in the ax88179_rx_fixup() function (Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-lowlatency
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-6.17
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management