CVE-2022-48864
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-48864 affects the Linux kernel's vdpa/mlx5 component. The vulnerability was discovered when it was found that the control virtual queue (vq) lacked proper validation for VIRTIONETCTRLMQVQPAIRSSET command requests from drivers. Specifically, there was no validation against the number of queue pairs to configure, and the system did not verify if multiqueue had been negotiated (Kernel Commit).

Technical details

The vulnerability exists in the Linux kernel's vdpa/mlx5 driver's handling of VIRTIONETCTRLMQVQPAIRSSET commands. When the control virtual queue receives this command request from a driver, the system failed to validate both the number of queue pairs to configure and whether multiqueue had been negotiated. The issue was introduced in commit 52893733f2c5 which added multiqueue support to vdpa/mlx5 (Kernel Commit).

Impact

This vulnerability could lead to a kernel panic due to uninitialized resources for the queues if a bogus request is sent by an untrusted driver. The impact is particularly severe because an untrusted driver could fake a multiqueue config request to a non-mq device, potentially causing system instability (Kernel Commit).

Mitigation and workarounds

The issue has been fixed by adding proper validation checks for the VIRTIONETCTRLMQVQPAIRSSET command. The fix includes verifying if multiqueue had been negotiated using MLX5FEATURE(mvdev, VIRTIONETFMQ) and validating the number of queue pairs against minimum and maximum allowed values (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management