VulnerabilityModified
CVE-2022-49260
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - fix the aead software fallback for engine Due to the subreq pointer misuse the private context memory.
MEDIUM 5.5EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - fix the aead software fallback for engine Due to the subreq pointer misuse the private context memory. The aead soft crypto occasionally casues the OS panic as setting the 64K page. Here is fix it.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.66% probability · 49th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0a2a464f863187f97e96ebc6384c052cafd4a54cPatch
- https://git.kernel.org/stable/c/40dba7c26e897c637e91312b35f664f1d4d0073cPatch
- https://git.kernel.org/stable/c/5c1149e2abe0b7489300736b8277b45b113de67fPatch
- https://git.kernel.org/stable/c/ef7b10f3cac7810ddcfd976304fd125aca33d144Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.