CVE-2022-49659
MediumIn the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_{read_fifo,echo_tx_event}(): shift timestamp to full 32 bits In commit 1be37d3b0414 ("can: m_can: fix periph RX path: use rx-offload to ensure skbs are sent from softirq context") the RX path for peripheral devices was switched to RX-offload. Received CAN frames are pushed to RX-offload together with a timestamp. RX-offload is designed to handle overflows of the timestamp correctly, if 32 bit timestamps are provided. The timestamps of m_can core are only 16 bits wide. So this patch shifts them to full 32 bit before passing them to RX-offload.
CVSS 3.1 score
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected versions
Linux kernel versions
5.13
and later are affected. Fixed in
5.15.54,
5.18.11,
5.19
and their respective stable series.
References
The following references provide additional information about CVE-2022-49659 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
-
PatchKernel patch commithttps://git.kernel.org/stable/c/2a2914a5bd7f38efe55a8372178146de82e0bce9
-
PatchKernel patch commithttps://git.kernel.org/stable/c/4c3333693f07313f5f0145a922f14a7d3c0f4f21
-
PatchKernel patch commithttps://git.kernel.org/stable/c/c7333f79888497bfd75dcd02a94eaf836dd1042c
Frequently asked questions
-
What is CVE-2022-49659?
CVE-2022-49659 is a Medium severity Linux kernel vulnerability with a CVSS score of 5.5 out of 10 . It affects Linux kernel versions from 5.13 onward and has been patched in 5.15.54, 5.18.11 and 5.19. CVE-2022-49659 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2022-49659?
CVE-2022-49659 has a CVSS score of 5.5 out of 10, rated Medium severity (CVSS 3.1). The vector string is
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. -
Is there a patch available for CVE-2022-49659?
Yes — CVE-2022-49659 has been patched. Fixed versions include 5.15.54, 5.18.11 and 5.19. If you are running Linux kernel 5.13 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2022-49659 actively exploited?
No — CVE-2022-49659 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.