The CVE describes an out-of-bounds read in the SMC protocol stack, but no vulnerable code was ever identified. The MITRE record lists the affected version as "Not Known" and references only two Red Hat bugzillas, the originating one of which was never made public.
The public bugzilla is closed as NOTABUG, with the statement "There was no shipped kernel version that was seen affected by this problem": https://bugzilla.redhat.com/show_bug.cgi?id=2044575 https://access.redhat.com/security/cve/CVE-2022-0400 SUSE reached the same conclusion independently, closing bsc#1195329 as RESOLVED / INVALID: https://www.suse.com/security/cve/CVE-2022-0400.html So did Debian, which marks it unimportant with the note "non issue, no security impact": https://security-tracker.debian.org/tracker/CVE-2022-0400 There is no commit in mainline referencing this CVE. The net/smc out-of-bounds fixes that landed in v5.18 (b1871fd48efc, 0558226cebee) are in local, privileged paths and are not linked to this CVE by any tracker. CC: Paul Barker <[email protected]> AI-Generated: Uses Claude (claude-opus-5) Signed-off-by: Junjie Cao <[email protected]> --- v3: no functional change since v2 v2: https://lore.kernel.org/openembedded-core/[email protected]/ meta/recipes-kernel/linux/cve-exclusion.inc | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/meta/recipes-kernel/linux/cve-exclusion.inc b/meta/recipes-kernel/linux/cve-exclusion.inc index ba8e467..be74672 100644 --- a/meta/recipes-kernel/linux/cve-exclusion.inc +++ b/meta/recipes-kernel/linux/cve-exclusion.inc @@ -214,3 +214,10 @@ KSM page deduplication, only reachable when KSM is enabled and opted into" # https://ubuntu.com/security/CVE-2021-3864 CVE_STATUS[CVE-2021-3864] = "unpatched: no accepted mainline fix, \ exploitation requires a relative kernel.core_pattern" + +# Never substantiated: no affected version, reproducer or commit was ever +# identified. Closed NOTABUG by Red Hat, INVALID by SUSE (bsc#1195329) and +# "non issue, no security impact" by Debian. +# https://bugzilla.redhat.com/show_bug.cgi?id=2044575 +CVE_STATUS[CVE-2022-0400] = "disputed: the reported net/smc out-of-bounds read \ +was never substantiated and was closed as not-a-bug by Red Hat, SUSE and Debian" -- 2.43.0
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#243229): https://lists.openembedded.org/g/openembedded-core/message/243229 Mute This Topic: https://lists.openembedded.org/mt/120714053/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
