CVE-2022-48626
published 2024-02-26CVE-2022-48626: In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path It was reported that the mmc host…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.31%
23.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
moxart: fix potential use-after-free on remove path
It was reported that the mmc host structure could be accessed after it
was freed in moxart_remove(), so fix this by saving the base register of
the device and using it instead of the pointer dereference.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.10-1 (bookworm) | linux 5.16.10-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1b66e94e6b9995323190f31c51d8e1a6f516627e < f5dc193167591e88797262ec78515a0cbe79ff5f | f5dc193167591e88797262ec78515a0cbe79ff5f |
| linux | linux | >= 1b66e94e6b9995323190f31c51d8e1a6f516627e < e6f580d0b3349646d4ee1ce0057eb273e8fb7e2e | e6f580d0b3349646d4ee1ce0057eb273e8fb7e2e |
| linux | linux | >= 1b66e94e6b9995323190f31c51d8e1a6f516627e < 9c25d5ff1856b91bd4365e813f566cb59aaa9552 | 9c25d5ff1856b91bd4365e813f566cb59aaa9552 |
| linux | linux | >= 1b66e94e6b9995323190f31c51d8e1a6f516627e < 3a0a7ec5574b510b067cfc734b8bdb6564b31d4e | 3a0a7ec5574b510b067cfc734b8bdb6564b31d4e |
| linux | linux | >= 1b66e94e6b9995323190f31c51d8e1a6f516627e < be93028d306dac9f5b59ebebd9ec7abcfc69c156 | be93028d306dac9f5b59ebebd9ec7abcfc69c156 |
| linux | linux | >= 1b66e94e6b9995323190f31c51d8e1a6f516627e < af0e6c49438b1596e4be8a267d218a0c88a42323 | af0e6c49438b1596e4be8a267d218a0c88a42323 |
| linux | linux | >= 1b66e94e6b9995323190f31c51d8e1a6f516627e < 7f901d53f120d1921f84f7b9b118e87e94b403c5 | 7f901d53f120d1921f84f7b9b118e87e94b403c5 |
| linux | linux | >= 1b66e94e6b9995323190f31c51d8e1a6f516627e < bd2db32e7c3e35bd4d9b8bbff689434a50893546 | bd2db32e7c3e35bd4d9b8bbff689434a50893546 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 3.16 < 4.9.301 | 4.9.301 |
| linux | linux_kernel | >= 4.10 < 4.14.266 | 4.14.266 |
| linux | linux_kernel | >= 4.15 < 4.19.229 | 4.19.229 |
| linux | linux_kernel | >= 4.20 < 5.4.179 | 5.4.179 |
| linux | linux_kernel | >= 5.11 < 5.15.23 | 5.15.23 |
| linux | linux_kernel | >= 5.16 < 5.16.9 | 5.16.9 |
| linux | linux_kernel | >= 5.5 < 5.10.100 | 5.10.100 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: moxart: fix potential use-after-free on remove path
vendor_redhat·2024-02-25·CVSS 7.8
CVE-2022-48626 [HIGH] CWE-416 kernel: moxart: fix potential use-after-free on remove path
kernel: moxart: fix potential use-after-free on remove path
In the Linux kernel, the following vulnerability has been resolved:
moxart: fix potential use-after-free on remove path
It was reported that the mmc host structure could be accessed after it
was freed in moxart_remove(), so fix this by saving the base register of
the device and using it instead of the pointer dereference.
A use-after-free flaw was found in the Linux kernel’s MOXART SD/MMC Host Controller driver. This flaw allows a local user to crash the system.
Statement: No Red Hat products are not affected by this flaw, as the MOXART SD/MMC Host Controller support (CONFIG_MMC_MOXART) is not enabled in any shipping kernel release.
Mitigation: Mitigation for this issue is either not available or the currently available option
Debian
CVE-2022-48626: linux - In the Linux kernel, the following vulnerability has been resolved: moxart: fix...
vendor_debian·2022·CVSS 7.8
CVE-2022-48626 [HIGH] CVE-2022-48626: linux - In the Linux kernel, the following vulnerability has been resolved: moxart: fix...
In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path It was reported that the mmc host structure could be accessed after it was freed in moxart_remove(), so fix this by saving the base register of the device and using it instead of the pointer dereference.
Scope: local
bookworm: resolved (fixed in 5.16.10-1)
bullseye: open
forky: resolved (fixed in 5.16.10-1)
sid: resolved (fixed in 5.16.10-1)
trixie: resolved (fixed in 5.16.10-1)
OSV
CVE-2022-48626: In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path It was reported that the mmc h
osv·2024-02-26·CVSS 7.8
CVE-2022-48626 [HIGH] CVE-2022-48626: In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path It was reported that the mmc h
In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path It was reported that the mmc host structure could be accessed after it was freed in moxart_remove(), so fix this by saving the base register of the device and using it instead of the pointer dereference.
GHSA
GHSA-4pqp-3cv2-mm87: In the Linux kernel, the following vulnerability has been resolved:
moxart: fix potential use-after-free on remove path
It was reported that the mmc
ghsa_unreviewed·2024-02-26
CVE-2022-48626 [HIGH] CWE-416 GHSA-4pqp-3cv2-mm87: In the Linux kernel, the following vulnerability has been resolved:
moxart: fix potential use-after-free on remove path
It was reported that the mmc
In the Linux kernel, the following vulnerability has been resolved:
moxart: fix potential use-after-free on remove path
It was reported that the mmc host structure could be accessed after it
was freed in moxart_remove(), so fix this by saving the base register of
the device and using it instead of the pointer dereference.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/3a0a7ec5574b510b067cfc734b8bdb6564b31d4ehttps://git.kernel.org/stable/c/7f901d53f120d1921f84f7b9b118e87e94b403c5https://git.kernel.org/stable/c/9c25d5ff1856b91bd4365e813f566cb59aaa9552https://git.kernel.org/stable/c/af0e6c49438b1596e4be8a267d218a0c88a42323https://git.kernel.org/stable/c/bd2db32e7c3e35bd4d9b8bbff689434a50893546https://git.kernel.org/stable/c/be93028d306dac9f5b59ebebd9ec7abcfc69c156https://git.kernel.org/stable/c/e6f580d0b3349646d4ee1ce0057eb273e8fb7e2ehttps://git.kernel.org/stable/c/f5dc193167591e88797262ec78515a0cbe79ff5fhttps://git.kernel.org/stable/c/3a0a7ec5574b510b067cfc734b8bdb6564b31d4ehttps://git.kernel.org/stable/c/7f901d53f120d1921f84f7b9b118e87e94b403c5https://git.kernel.org/stable/c/9c25d5ff1856b91bd4365e813f566cb59aaa9552https://git.kernel.org/stable/c/af0e6c49438b1596e4be8a267d218a0c88a42323https://git.kernel.org/stable/c/bd2db32e7c3e35bd4d9b8bbff689434a50893546https://git.kernel.org/stable/c/be93028d306dac9f5b59ebebd9ec7abcfc69c156https://git.kernel.org/stable/c/e6f580d0b3349646d4ee1ce0057eb273e8fb7e2ehttps://git.kernel.org/stable/c/f5dc193167591e88797262ec78515a0cbe79ff5f
2024-02-26
Published