CVE-2022-45888Race Condition in Linux

Severity
6.4MEDIUMNVD
EPSS
0.0%
top 95.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25

Description

An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device.

CVSS vector

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.5 | Impact: 5.9

Affected Packages6 packages

Debianlinux/linux_kernel< 6.1.119-1+2
debiandebian/linux< linux 6.1.119-1 (bookworm)
debiandebian/linux-6.1< linux 6.1.119-1 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-9qv2-q963-rpq5: An issue was discovered in the Linux kernel through 62022-11-25
OSV
CVE-2022-45888: An issue was discovered in the Linux kernel through 62022-11-25

📋Vendor Advisories

3
Microsoft
An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device.2022-11-08
Red Hat
kernel: use-after-free due to race condition in drivers/char/xillybus/xillyusb.c2022-10-22
Debian
CVE-2022-45888: linux - An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus...2022