cbcvebase.
CVE-2022-48641
published 2024-04-28

CVE-2022-48641: In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix memory leak when blob is malformed The bug fix was incomplete, it…

PriorityP415medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix memory leak when blob is malformed The bug fix was incomplete, it "replaced" crash with a memory leak. The old code had an assignment to "ret" embedded into the conditional, restore this.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux>= 160c4eb47db03b96c0c425358e7595ebefe8094d < 11ebf32fde46572b0aaf3c2bdd97d923ef5a03ab11ebf32fde46572b0aaf3c2bdd97d923ef5a03ab
linuxlinux>= 1b2c5428f773d60c116c7b1e390432e0cfb63cd6 < d5917b7af7cae0e2804f9d127a03268035098b7fd5917b7af7cae0e2804f9d127a03268035098b7f
linuxlinux>= 358765beb836f5fc2ed26b5df4140d5d3548ac11 < 1e98318af2f163eadaff815abcef38d27ca92c1e1e98318af2f163eadaff815abcef38d27ca92c1e
linuxlinux>= 4.14.292 < 4.14.2954.14.295
linuxlinux>= 4.19.257 < 4.19.2604.19.260
linuxlinux>= 5.10.140 < 5.10.1465.10.146
linuxlinux>= 5.15.64 < 5.15.715.15.71
linuxlinux>= 5.19.6 < 5.19.125.19.12
linuxlinux>= 5.4.212 < 5.4.2155.4.215
linuxlinux>= 624c30521233e110cf50ba01980a591e045036ae < ebd97dbe3c55d68346b9c5fb00634a7f5b10bbeeebd97dbe3c55d68346b9c5fb00634a7f5b10bbee
linuxlinux>= 7997eff82828304b780dc0a39707e1946d6f1ebf < 62ce44c4fff947eebdf10bb582267e686e6835c962ce44c4fff947eebdf10bb582267e686e6835c9
linuxlinux>= afd01382594d643e1adeb16826423b418cdf8b8b < 754e8b74281dd54a324698803483f47cf3355ae1754e8b74281dd54a324698803483f47cf3355ae1
linuxlinux>= e53cfa017bf4575d0b948a8f45313ef66d897136 < 38cf372b17f0a5f35c1b716a100532d539f0eb3338cf372b17f0a5f35c1b716a100532d539f0eb33
linuxlinux_kernel>= 0 < 5.10.148-15.10.148-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 4.14.292 < 4.14.2954.14.295
linuxlinux_kernel>= 4.19.257 < 4.19.2604.19.260
linuxlinux_kernel>= 5.10.140 < 5.10.1465.10.146
linuxlinux_kernel>= 5.15.64 < 5.15.715.15.71
linuxlinux_kernel>= 5.19.6 < 5.19.125.19.12
linuxlinux_kernel>= 5.4.212 < 5.4.2155.4.215

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.