ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference
Summary
| CVE | CVE-2022-48999 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-10-21 20:15:11 UTC |
| Updated | 2026-08-04 10:17:30 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference Gwangun Jung reported a slab-out-of-bounds access in fib_nh_match: fib_nh_match+0xf98/0x1130 linux-6.0-rc7/net/ipv4/fib_semantics.c:961 fib_table_delete+0x5f3/0xa40 linux-6.0-rc7/net/ipv4/fib_trie.c:1753 inet_rtm_delroute+0x2b3/0x380 linux-6.0-rc7/net/ipv4/fib_frontend.c:874 Separate nexthop objects are mutually exclusive with the legacy multipath spec. Fix fib_nh_match to return if the config for the to be deleted route contains a multipath spec while the fib_info is using a nexthop object. |
Risk And Classification
Primary CVSS: v3.1 7.1 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Problem Types: CWE-125
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.1 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.1 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
| 3.1 | CNA | DECLARED | 7.1 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 493ced1ac47c48bb86d9d4e8e87df8592be85a0e cc3cd130ecfb8b0ae52e235e487bae3f16a24a32 git | Not specified |
| CNA | Linux | Linux | affected 493ced1ac47c48bb86d9d4e8e87df8592be85a0e 0b5394229ebae09afc07aabccb5ffd705ffd250e git | Not specified |
| CNA | Linux | Linux | affected 493ced1ac47c48bb86d9d4e8e87df8592be85a0e 25174d91e4a32a24204060d283bd5fa6d0ddf133 git | Not specified |
| CNA | Linux | Linux | affected 493ced1ac47c48bb86d9d4e8e87df8592be85a0e bb20a2ae241be846bc3c11ea4b3a3c69e41d51f2 git | Not specified |
| CNA | Linux | Linux | affected 493ced1ac47c48bb86d9d4e8e87df8592be85a0e 61b91eb33a69c3be11b259c5ea484505cd79f883 git | Not specified |
| CNA | Linux | Linux | affected 5.3 | Not specified |
| CNA | Linux | Linux | unaffected 5.3 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.226 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.158 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.82 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.0.12 6.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/61b91eb33a69c3be11b259c5ea484505cd79f883 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/bb20a2ae241be846bc3c11ea4b3a3c69e41d51f2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/cc3cd130ecfb8b0ae52e235e487bae3f16a24a32 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/0b5394229ebae09afc07aabccb5ffd705ffd250e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/25174d91e4a32a24204060d283bd5fa6d0ddf133 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.