CVE-2022-2964
Linux Kernel vulnerability analysis and mitigation

Overview

A flaw was discovered in the Linux kernel's driver for the ASIX AX88179178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability (CVE-2022-2964) was identified in kernel versions prior to 5.17 and contains multiple out-of-bounds reads and possible out-of-bounds writes in the ax88179rx_fixup() function. The issue was discovered by Jann Horn and was fixed in kernel version 5.17 (Kernel Fix).

Technical details

The vulnerability exists in the ax88179rxfixup() function within the Linux kernel's driver for ASIX AX88179_178A USB Ethernet devices. The issue manifests as multiple out-of-bounds read operations and potential out-of-bounds write operations. The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (High), with the following vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NetApp Security).

Impact

Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or a denial of service (DoS) condition. A local attacker with physical access could potentially exploit this vulnerability by plugging in a specially crafted USB device to cause system crashes or possibly execute arbitrary code (Ubuntu Security).

Mitigation and workarounds

The primary mitigation is to update to Linux kernel version 5.17 or later, which contains the fix for this vulnerability. Multiple Linux distributions have released security updates to address this issue, including Red Hat Enterprise Linux, Ubuntu, and Debian. The fix was implemented through a patch that corrects the out-of-bounds operations in the ax88179rxfixup() function (Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management