CVE-2022-3545
ECS: Improper Restriction of Operations within the Bounds of a Memory Buffer (CVE-2022-3545)
Affected
- Dell/ECS
3.8.1.0..*
Description
A vulnerability was found in area_cache_get in drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c in the Netronome Flow Processor (NFP) driver in the Linux kernel. This flaw allows a manipulation that may lead to a use-after-free issue.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
3.8.1.0Metrics
Show all metrics
Weakness classes (CWE)
CWE-119Class
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
cwe.mitre.org →
References & sources
- https://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec-next.git/commit/?id=02e1a114fdb71e59ee6770294166c30d437bf86a
- https://vuldb.com/?id.211045
- https://security.netapp.com/advisory/ntap-20221223-0003/
- https://www.debian.org/security/2023/dsa-5324vendor-advisory
- https://lists.debian.org/debian-lts-announce/2023/03/msg00000.htmlmailing-list
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.htmlmailing-list