From: Junjie Cao <junjie.cao@linux.dev>
To: openembedded-core@lists.openembedded.org
Cc: paul@pbarker.dev
Subject: [OE-core][PATCH v3 4/9] cve-exclusions: set status for CVE-2022-0400
Date: Wed, 12 Aug 2026 02:28:37 -0500 [thread overview]
Message-ID: <20260812072842.1176341-5-junjie.cao@linux.dev> (raw)
In-Reply-To: <20260812072842.1176341-1-junjie.cao@linux.dev>
The CVE describes an out-of-bounds read in the SMC protocol stack, but
no vulnerable code was ever identified. The MITRE record lists the
affected version as "Not Known" and references only two Red Hat
bugzillas, the originating one of which was never made public.
The public bugzilla is closed as NOTABUG, with the statement "There was
no shipped kernel version that was seen affected by this problem":
https://bugzilla.redhat.com/show_bug.cgi?id=2044575
https://access.redhat.com/security/cve/CVE-2022-0400
SUSE reached the same conclusion independently, closing bsc#1195329 as
RESOLVED / INVALID:
https://www.suse.com/security/cve/CVE-2022-0400.html
So did Debian, which marks it unimportant with the note "non issue, no
security impact":
https://security-tracker.debian.org/tracker/CVE-2022-0400
There is no commit in mainline referencing this CVE. The net/smc
out-of-bounds fixes that landed in v5.18 (b1871fd48efc, 0558226cebee)
are in local, privileged paths and are not linked to this CVE by any
tracker.
CC: Paul Barker <paul@pbarker.dev>
AI-Generated: Uses Claude (claude-opus-5)
Signed-off-by: Junjie Cao <junjie.cao@linux.dev>
---
v3: no functional change since v2
v2: https://lore.kernel.org/openembedded-core/20260803084827.1348810-1-junjie.cao@linux.dev/
meta/recipes-kernel/linux/cve-exclusion.inc | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/meta/recipes-kernel/linux/cve-exclusion.inc b/meta/recipes-kernel/linux/cve-exclusion.inc
index ba8e467..be74672 100644
--- a/meta/recipes-kernel/linux/cve-exclusion.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion.inc
@@ -214,3 +214,10 @@ KSM page deduplication, only reachable when KSM is enabled and opted into"
# https://ubuntu.com/security/CVE-2021-3864
CVE_STATUS[CVE-2021-3864] = "unpatched: no accepted mainline fix, \
exploitation requires a relative kernel.core_pattern"
+
+# Never substantiated: no affected version, reproducer or commit was ever
+# identified. Closed NOTABUG by Red Hat, INVALID by SUSE (bsc#1195329) and
+# "non issue, no security impact" by Debian.
+# https://bugzilla.redhat.com/show_bug.cgi?id=2044575
+CVE_STATUS[CVE-2022-0400] = "disputed: the reported net/smc out-of-bounds read \
+was never substantiated and was closed as not-a-bug by Red Hat, SUSE and Debian"
--
2.43.0
next prev parent reply other threads:[~2026-08-12 5:31 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-12 7:28 [OE-core][PATCH v3 0/9] cve-exclusions: triage nine kernel CVEs lacking upstream fix data Junjie Cao
2026-08-12 7:28 ` [OE-core][PATCH v3 1/9] cve-exclusions: set status for CVE-2019-14899 Junjie Cao
2026-08-12 7:28 ` [OE-core][PATCH v3 2/9] cve-exclusions: set status for CVE-2021-3714 Junjie Cao
2026-08-12 7:28 ` [OE-core][PATCH v3 3/9] cve-exclusions: set status for CVE-2021-3864 Junjie Cao
2026-08-12 7:28 ` Junjie Cao [this message]
2026-08-12 7:28 ` [OE-core][PATCH v3 5/9] cve-exclusions: set status for CVE-2022-1247 Junjie Cao
2026-08-12 7:28 ` [OE-core][PATCH v3 6/9] cve-exclusions: set status for CVE-2022-4543 Junjie Cao
2026-08-12 7:28 ` [OE-core][PATCH v3 7/9] cve-exclusions: set status for CVE-2023-3397 Junjie Cao
2026-08-12 7:28 ` [OE-core][PATCH v3 8/9] cve-exclusions: set status for CVE-2023-6238 Junjie Cao
2026-08-12 7:28 ` [OE-core][PATCH v3 9/9] cve-exclusions: set status for CVE-2023-6240 Junjie Cao
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260812072842.1176341-5-junjie.cao@linux.dev \
--to=junjie.cao@linux.dev \
--cc=openembedded-core@lists.openembedded.org \
--cc=paul@pbarker.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.