{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2022-49725","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-02-26T02:21:30.447Z","datePublished":"2025-02-26T02:24:37.349Z","dateUpdated":"2026-08-05T08:56:07.991Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T08:56:07.991Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: Fix call trace in setup_tx_descriptors\n\nAfter PF reset and ethtool -t there was call trace in dmesg\nsometimes leading to panic. When there was some time, around 5\nseconds, between reset and test there were no errors.\n\nProblem was that pf reset calls i40e_vsi_close in prep_for_reset\nand ethtool -t calls i40e_vsi_close in diag_test. If there was not\nenough time between those commands the second i40e_vsi_close starts\nbefore previous i40e_vsi_close was done which leads to crash.\n\nAdd check to diag_test if pf is in reset and don't start offline\ntests if it is true.\nAdd netif_info(\"testing failed\") into unhappy path of i40e_diag_test()"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through the local SIOCETHTOOL ETHTOOL_TEST ioctl path (__dev_ethtool → ethtool_self_test → i40e_diag_test → i40e_close/i40e_do_reset), not via remote packet processing or an adjacent-link protocol.\nAC:L - An attacker who can drive PF reset and immediately run ethtool -t controls both sides of the race; the multi-second RESET_RECOVERY_PENDING window (prep_for_reset without rtnl on the async service-task path, then rebuild) is large enough to hit reliably by issuing both operations back-to-back.\nPR:L - ETHTOOL_TEST requires ns_capable(net->user_ns, CAP_NET_ADMIN), which is available in a user-namespace–owned netns with a delegated i40e PF, matching prior Intel ethernet/ethtool scoring (e.g. ice AF_XDP CAP_NET_ADMIN paths).\nUI:N - The attacker issues the ethtool self-test (and the concurrent reset trigger) from their own process; no separate victim action such as mounting media or opening a file is required.\nS:U - The race corrupts host-kernel i40e ring/VSI state within the same OS security authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - Overlapping i40e_vsi_close calls free TX/RX resources outside the __I40E_VSI_DOWN bit (desc check then kfree(tx_bi)/dma_free_coherent with no serialization), yielding a heap double-free/UAF that can be leveraged for high-impact kernel memory disclosure.\nI:H - The same unsynchronized double-free/UAF of tx_bi and DMA descriptor memory is exploitable heap corruption that, per UAF guidance, enables write and control-flow hijack primitives beyond a pure crash.\nA:H - The race produces kernel call traces and panics (including WARN_ON(tx_ring->tx_bi) in i40e_setup_tx_descriptors and faults from the double-free/UAF), which is a full availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/intel/i40e/i40e_ethtool.c"],"versions":[{"version":"e17bc411aea8fbebc51857037f104ab09f765120","lessThan":"5ba9956ca57e361fb13ea369bb753eb33177acc7","status":"affected","versionType":"git"},{"version":"e17bc411aea8fbebc51857037f104ab09f765120","lessThan":"15950157e2c24865b696db1c9ccc72743ae0e967","status":"affected","versionType":"git"},{"version":"e17bc411aea8fbebc51857037f104ab09f765120","lessThan":"ff6e03fe84bc917bb0c907d02de668c2fe101712","status":"affected","versionType":"git"},{"version":"e17bc411aea8fbebc51857037f104ab09f765120","lessThan":"814092927a215f5ca6c08249ec72a205e0b473cd","status":"affected","versionType":"git"},{"version":"e17bc411aea8fbebc51857037f104ab09f765120","lessThan":"0a4e5a3dc5e41212870e6043895ae02455c93f63","status":"affected","versionType":"git"},{"version":"e17bc411aea8fbebc51857037f104ab09f765120","lessThan":"322271351b0e41565171e4cce70ea41854fac115","status":"affected","versionType":"git"},{"version":"e17bc411aea8fbebc51857037f104ab09f765120","lessThan":"fd5855e6b1358e816710afee68a1d2bc685176ca","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/intel/i40e/i40e_ethtool.c"],"versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","status":"unaffected","versionType":"semver"},{"version":"4.14.285","lessThanOrEqual":"4.14.*","status":"unaffected","versionType":"semver"},{"version":"4.19.249","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.200","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.124","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.49","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"5.18.6","lessThanOrEqual":"5.18.*","status":"unaffected","versionType":"semver"},{"version":"5.19","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"4.14.285"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"4.19.249"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.4.200"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.10.124"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.15.49"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.18.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.19"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5ba9956ca57e361fb13ea369bb753eb33177acc7"},{"url":"https://git.kernel.org/stable/c/15950157e2c24865b696db1c9ccc72743ae0e967"},{"url":"https://git.kernel.org/stable/c/ff6e03fe84bc917bb0c907d02de668c2fe101712"},{"url":"https://git.kernel.org/stable/c/814092927a215f5ca6c08249ec72a205e0b473cd"},{"url":"https://git.kernel.org/stable/c/0a4e5a3dc5e41212870e6043895ae02455c93f63"},{"url":"https://git.kernel.org/stable/c/322271351b0e41565171e4cce70ea41854fac115"},{"url":"https://git.kernel.org/stable/c/fd5855e6b1358e816710afee68a1d2bc685176ca"}],"title":"i40e: Fix call trace in setup_tx_descriptors","x_generator":{"engine":"bippy-1.2.0"}}}}