CVE-2022-3643
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-3643 is a vulnerability discovered in the Xen netback driver of the Linux kernel that allows guests to trigger NIC interface reset/abort/crash. The vulnerability was disclosed in December 2022 and affects Linux-based network backends with kernel versions 3.19 and newer. The issue occurs when a guest sends network packets with split headers, causing the netback driver to forward malformed packet buffers to the networking core (XEN Advisory).

Technical details

The vulnerability stems from an unwritten assumption in the Linux network stack where packet protocol headers are expected to be contained within the linear section of the SKB (Socket Buffer). When this assumption is violated, certain NICs behave incorrectly. The issue has been confirmed to affect Cisco (enic) and Broadcom NetXtrem II BCM5780 (bnx2x) drivers, though other NICs/drivers may also be vulnerable. The vulnerability has been assigned a CVSS score of 6.5 (Medium) (Ubuntu Security).

Impact

An unprivileged guest can cause network Denial of Service (DoS) of the host by sending network packets to the backend, resulting in the related physical NIC to reset, abort, or crash. While data corruption or privilege escalation seem unlikely, they have not been completely ruled out (XEN Advisory).

Mitigation and workarounds

Several mitigation strategies are available: 1) Using another PV network backend (e.g., the qemu-based 'qnic' backend), 2) Using a dedicated network driver domain per guest. For permanent resolution, system administrators should apply the security patches provided for their specific Linux distribution (XEN Advisory, Ubuntu Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-fips
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-fips
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-oracle-6.8
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-nvidia-6.8
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • kernel-devel
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management