CVE-2022-48882
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-48882 is a vulnerability in the Linux kernel affecting the MACsec (MAC Security) functionality in the Mellanox MLX5 driver. The vulnerability was discovered in the net/mlx5e component and involves a potential null pointer dereference when updating MAC security entity (SecY). This issue affects Linux kernel versions from 6.1 up to (excluding) 6.1.7 (NVD).

Technical details

The vulnerability occurs in the hardware offload path when updating a MAC security entity (SecY). Specifically, when the extended packet number (EPN) is enabled, the salt and SSCI attributes are retrieved using the MACsec driver rx_sa context. However, this context is unavailable when updating a SecY property such as encoding-sa, leading to a null pointer dereference. The issue has been assigned a CVSS v3.1 Base Score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

The vulnerability primarily affects system availability. When successfully exploited, it can cause a null pointer dereference in the kernel, potentially leading to system crashes or denial of service conditions. The CVSS scoring indicates no impact on confidentiality or integrity, but a high impact on availability (NVD).

Mitigation and workarounds

The vulnerability has been fixed by modifying the code to use the provided SA to set the salt and SSCI attributes instead of relying on the rxsa context. The fix is implemented in the kernel patch that changes the attribute retrieval method in the mlx5emacsecinitsa function (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management