
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-48841 is a vulnerability in the Linux kernel's Intel ICE driver that allows for a NULL pointer dereference in the iceupdatevsitxring_stats() function. The vulnerability was discovered in early 2022 and affects Linux kernel versions up to (excluding) 5.16.17 and 5.17 release candidates (Kernel Git, NVD).
The vulnerability occurs in the routine that updates Tx ring stats in the Intel ICE driver. The issue arises because while stats and bytes are only updated when the ring pointer is valid, the code later attempts to access the ring to propagate gathered Tx stats onto VSI stats without checking for NULL. This could lead to a NULL pointer dereference. The vulnerability has been assigned a CVSS v3.1 score with vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).
The vulnerability can cause a NULL pointer dereference in the Linux kernel's Intel ICE driver, which could lead to a system crash or denial of service condition (Kernel Git).
The vulnerability was fixed by changing the existing logic to move to the next ring when the ring is NULL. The fix was implemented in patch f153546913bada41a811722f2c6d17c3243a0333 and backported to stable kernel versions (Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."