CVE Database
/

CVE-2022-49234

Back to search

CVE-2022-49234

Published: Feb 26, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: net: dsa: Avoid cross-chip syncing of VLAN filtering Changes to VLAN filtering are not applicable to cross-chip notifications. On a system like this: .-----. .-----. .-----. | sw1 +---+ sw2 +---+ sw3 | '-1-2-' '-1-2-' '-1-2-' Before this change, upon sw1p1 leaving a bridge, a call to dsa_port_vlan_filtering would also be made to sw2p1 and sw3p1. In this scenario: .---------. .-----. .-----. | sw1 +---+ sw2 +---+ sw3 | '-1-2-3-4-' '-1-2-' '-1-2-' When sw1p4 would leave a bridge, dsa_port_vlan_filtering would be called for sw2 and sw3 with a non-existing port - leading to array out-of-bounds accesses and crashes on mv88e6xxx.

VendorProductVersions

Linux

Linux

affected
d371b7c92d190448f3ccbf082c90bf929285f648 - < e1f2a4dd8d433eec393d09273a78a3d3551339cf
affected
d371b7c92d190448f3ccbf082c90bf929285f648 - < 108dc8741c203e9d6ce4e973367f1bac20c7192b

Linux

Linux

affected
5.2
unaffected
0 - < 5.2
unaffected
5.17.2 - <= 5.17.*
unaffected
5.18 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now