<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 11:01:38 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-48980 — net: dsa: sja1105: avoid out of bounds access in sja1105_init_l2_policing()</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-48980</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: dsa: sja1105: avoid out of bounds access in sja1105_init_l2_policing()&lt;/p&gt;
&lt;p&gt;The SJA1105 family has 45 L2 policing table entries
(SJA1105_MAX_L2_POLICING_COUNT) and SJA1110 has 110
(SJA1110_MAX_L2_POLICING_COUNT). Keeping the table structure but
accounting for the difference in port count (5 in SJA1105 vs 10 in
SJA1110) does not fully explain the difference. Rather, the SJA1110 also
has L2 ingress policers for multicast traffic. If a packet is classified
as multicast, it will be processed by the policer index 99 + SRCPORT.&lt;/p&gt;
&lt;p&gt;The sja1105_init_l2_policing() function initializes all L2 policers such
that they don&amp;#39;t interfere with normal packet reception by default. To have
a common code between SJA1105 and SJA1110, the index of the multicast
policer for the port is calculated because it&amp;#39;s an index that is out of
bounds for SJA1105 but in bounds for SJA1110, and a bounds check is
performed.&lt;/p&gt;
&lt;p&gt;The code fails to do the proper thing when determining what to do with the
multicast policer of port 0 on SJA1105 (ds-&amp;gt;num_ports = 5). The &amp;#34;mcast&amp;#34;
index will be equal to 45, which is also equal to
table-&amp;gt;ops-&amp;gt;max_entry_count (SJA1105_MAX_L2_POLICING_COUNT). So it passes
through the check. But at the same time, SJA1105 doesn&amp;#39;t have multicast
policers. So the code programs the SHARINDX field of an out-of-bounds
element in the L2 Policing table of the static config.&lt;/p&gt;
&lt;p&gt;The comparison between index 45 and 45 entries should have de…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: dsa: sja1105: avoid out of bounds access in sja1105_init_l2_policing()&lt;/p&gt;
&lt;p&gt;The SJA1105 family has 45 L2 policing table entries
(SJA1105_MAX_L2_POLICING_COUNT) and SJA1110 has 110
(SJA1110_MAX_L2_POLICING_COUNT). Keeping the table structure but
accounting for the difference in port count (5 in SJA1105 vs 10 in
SJA1110) does not fully explain the difference. Rather, the SJA1110 also
has L2 ingress policers for multicast traffic. If a packet is classified
as multicast, it will be processed by the policer index 99 + SRCPORT.&lt;/p&gt;
&lt;p&gt;The sja1105_init_l2_policing() function initializes all L2 policers such
that they don&amp;#39;t interfere with normal packet reception by default. To have
a common code between SJA1105 and SJA1110, the index of the multicast
policer for the port is calculated because it&amp;#39;s an index that is out of
bounds for SJA1105 but in bounds for SJA1110, and a bounds check is
performed.&lt;/p&gt;
&lt;p&gt;The code fails to do the proper thing when determining what to do with the
multicast policer of port 0 on SJA1105 (ds-&amp;gt;num_ports = 5). The &amp;#34;mcast&amp;#34;
index will be equal to 45, which is also equal to
table-&amp;gt;ops-&amp;gt;max_entry_count (SJA1105_MAX_L2_POLICING_COUNT). So it passes
through the check. But at the same time, SJA1105 doesn&amp;#39;t have multicast
policers. So the code programs the SHARINDX field of an out-of-bounds
element in the L2 Policing table of the static config.&lt;/p&gt;
&lt;p&gt;The comparison between index 45 and 45 entries should have de…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-48980</guid>
    </item>
  </channel>
</rss>
