Revision Date: | 2023-02-11 | Version: | 1 |
Title: | CVE-2022-2308 |
Description: |
A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of the device config space is in line with the features advertised by the VDUSE userspace application. In case of a mismatch, Virtio drivers config read helpers do not initialize the memory indirectly passed to vduse_vdpa_get_config() returning uninitialized memory from the stack. This could cause undefined behavior or data leaks in Virtio drivers.
|
Family: | unix | Class: | vulnerability |
Status: | | Reference(s): | Mitre CVE-2022-2308 SUSE CVE-2022-2308
|
Platform(s): | SUSE Linux Enterprise High Performance Computing 12 SP5 SUSE Linux Enterprise Micro 5.3 SUSE Linux Enterprise Server 12 SP5 SUSE Linux Enterprise Server for SAP Applications 12 SP4 SUSE Linux Enterprise Server for SAP Applications 12 SP5 SUSE Linux Enterprise Server for SAP Applications 15 SP2
| Product(s): | |
Definition Synopsis |
SUSE Linux Enterprise Micro 5.3 is installed AND kernel-default is not affected
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
AND
kernel-default is not affected
OR kernel-source is not affected
OR kernel-source-azure is not affected
OR Package Information
SUSE Linux Enterprise Server 12 SP5 is installed
AND
kernel-default is not affected
OR kernel-default-base is not affected
OR kernel-default-devel is not affected
OR kernel-default-man is not affected
OR kernel-devel is not affected
OR kernel-macros is not affected
OR kernel-source is not affected
OR kernel-devel-azure is not affected
OR kernel-source-azure is not affected
|
Definition Synopsis |
SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
AND Package Information
kernel-default is not affected
OR kernel-default-devel is not affected
OR reiserfs-kmp-default is not affected
OR kernel-devel is not affected
OR kernel-macros is not affected
OR kernel-source is not affected
|
Definition Synopsis |
SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
AND Package Information
kernel-default is not affected
OR kernel-default-base is not affected
OR kernel-default-devel is not affected
OR kernel-devel is not affected
OR kernel-macros is not affected
OR kernel-source is not affected
|