diff mbox series

[v2,04/10] cve-exclusion: set status for CVE-2022-0400

Message ID 20260803084827.1348810-5-junjie.cao@linux.dev
State New
Headers show
Series cve-exclusion: triage ten kernel CVEs lacking upstream fix data | expand

Commit Message

Junjie Cao Aug. 3, 2026, 8:48 a.m. UTC
The CVE describes an out-of-bounds read in the SMC protocol stack, but
no vulnerable code was ever identified. The MITRE record lists the
affected version as "Not Known" and references only two Red Hat
bugzillas, the originating one of which was never made public.

The public bugzilla is closed as NOTABUG, with the statement "There was
no shipped kernel version that was seen affected by this problem":

  https://bugzilla.redhat.com/show_bug.cgi?id=2044575
  https://access.redhat.com/security/cve/CVE-2022-0400

SUSE reached the same conclusion independently, closing bsc#1195329 as
RESOLVED / INVALID:

  https://www.suse.com/security/cve/CVE-2022-0400.html

So did Debian, which marks it unimportant with the note "non issue, no
security impact":

  https://security-tracker.debian.org/tracker/CVE-2022-0400

There is no commit in mainline referencing this CVE. The net/smc
out-of-bounds fixes that landed in v5.18 (b1871fd48efc, 0558226cebee)
are in local, privileged paths and are not linked to this CVE by any
tracker.

CC: Paul Barker <paul@pbarker.dev>
AI-Generated: Uses Claude (claude-opus-5)
Signed-off-by: Junjie Cao <junjie.cao@linux.dev>
---
changes in v2:
- split out of the single combined patch, one CVE per patch as requested
- added primary source links (disclosures, distribution trackers, mailing
  list threads, upstream commits) to every commit message
- added the three CVEs with no upstream fix as "unpatched" entries instead
  of leaving them undocumented
- disclosed AI assistance per the contributor guide

v1: https://lore.kernel.org/openembedded-core/20260802143444.1178575-1-junjie.cao@linux.dev/

 meta/recipes-kernel/linux/cve-exclusion.inc | 7 +++++++
 1 file changed, 7 insertions(+)
diff mbox series

Patch

diff --git a/meta/recipes-kernel/linux/cve-exclusion.inc b/meta/recipes-kernel/linux/cve-exclusion.inc
index d7ae3b03..0ae3a0d6 100644
--- a/meta/recipes-kernel/linux/cve-exclusion.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion.inc
@@ -212,3 +212,10 @@  KSM page deduplication, closed WONTFIX by Red Hat, no upstream fix planned"
 # https://www.openwall.com/lists/oss-security/2021/10/20/2
 CVE_STATUS[CVE-2021-3864] = "upstream-wontfix: no accepted mainline fix after \
 several attempts, exploitation requires a relative kernel.core_pattern"
+
+# Never substantiated: no affected version, reproducer or commit was ever
+# identified. Closed NOTABUG by Red Hat, INVALID by SUSE (bsc#1195329) and
+# "non issue, no security impact" by Debian.
+# https://bugzilla.redhat.com/show_bug.cgi?id=2044575
+CVE_STATUS[CVE-2022-0400] = "disputed: the reported net/smc out-of-bounds read \
+was never substantiated and was closed as not-a-bug by Red Hat, SUSE and Debian"