[OEM-5.14, OEM-5.17][PATCH 0/1] CVE-2022-3545

Yuxuan Luo yuxuan.luo at canonical.com
Fri Jan 20 21:15:51 UTC 2023


[Impact]
Under certain circumstance, the nfp has an use-after-free vulnerability.
The generic kernels were patched, but not OEM kernels.

[Backport]
They are all clean cherry-picks.

[Potential Regression]
Regression is scoped in nfp_cppcore.c

[Test]
Compile tested and smoked tested on generic kernels.
 
Jialiang Wang (1):
  nfp: fix use-after-free in area_cache_get()

 drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

-- 
2.34.1




More information about the kernel-team mailing list