CVE-2022-48695
published 2024-05-03CVE-2022-48695: In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix use-after-free warning Fix the following use-after-free warning which is…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpt3sas: Fix use-after-free warning
Fix the following use-after-free warning which is observed during
controller reset:
refcount_t: underflow; use-after-free.
WARNING: CPU: 23 PID: 5399 at lib/refcount.c:28 refcount_warn_saturate+0xa6/0xf0
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.19.11-1 (bookworm) | linux 5.19.11-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 146b16c8071f5f6c67895d15beeee1163f5107c4 < b8fc9e91b931215110ba824d1a2983c5f60b6f82 | b8fc9e91b931215110ba824d1a2983c5f60b6f82 |
| linux | linux | >= 146b16c8071f5f6c67895d15beeee1163f5107c4 < d4959d09b76eb7a4146f5133962b88d3bddb63d6 | d4959d09b76eb7a4146f5133962b88d3bddb63d6 |
| linux | linux | >= 146b16c8071f5f6c67895d15beeee1163f5107c4 < 82efb917eeb27454dc4c6fe26432fc8f6c75bc16 | 82efb917eeb27454dc4c6fe26432fc8f6c75bc16 |
| linux | linux | >= 146b16c8071f5f6c67895d15beeee1163f5107c4 < 5682c94644fde72f72bded6580c38189ffc856b5 | 5682c94644fde72f72bded6580c38189ffc856b5 |
| linux | linux | >= 146b16c8071f5f6c67895d15beeee1163f5107c4 < ea10a652ad2ae2cf3eced6f632a5c98f26727057 | ea10a652ad2ae2cf3eced6f632a5c98f26727057 |
| linux | linux | >= 146b16c8071f5f6c67895d15beeee1163f5107c4 < 6229fa494a5949be209bc73afbc5d0a749c2e3c7 | 6229fa494a5949be209bc73afbc5d0a749c2e3c7 |
| linux | linux | >= 146b16c8071f5f6c67895d15beeee1163f5107c4 < 41acb064c4e013808bc7d5fc1b506fa449425b0b | 41acb064c4e013808bc7d5fc1b506fa449425b0b |
| linux | linux | >= 146b16c8071f5f6c67895d15beeee1163f5107c4 < 991df3dd5144f2e6b1c38b8d20ed3d4d21e20b34 | 991df3dd5144f2e6b1c38b8d20ed3d4d21e20b34 |
| linux | linux_kernel | < 4.9.328 | 4.9.328 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.148-1 | 5.10.148-1 |
| linux | linux_kernel | >= 0 < 5.19.11-1 | 5.19.11-1 |
| linux | linux_kernel | >= 0 < 5.19.11-1 | 5.19.11-1 |
| linux | linux_kernel | >= 0 < 5.19.11-1 | 5.19.11-1 |
| linux | linux_kernel | >= 4.10 < 4.14.293 | 4.14.293 |
| linux | linux_kernel | >= 4.15 < 4.19.258 | 4.19.258 |
| linux | linux_kernel | >= 4.20 < 5.4.213 | 5.4.213 |
| linux | linux_kernel | >= 5.11 < 5.15.168 | 5.15.168 |
| linux | linux_kernel | >= 5.16 < 5.19.9 | 5.19.9 |
| linux | linux_kernel | >= 5.5 < 5.10.143 | 5.10.143 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: scsi: mpt3sas: Fix use-after-free warning
vendor_redhat·2024-05-03·CVSS 7.8
CVE-2022-48695 [HIGH] kernel: scsi: mpt3sas: Fix use-after-free warning
kernel: scsi: mpt3sas: Fix use-after-free warning
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpt3sas: Fix use-after-free warning
Fix the following use-after-free warning which is observed during
controller reset:
refcount_t: underflow; use-after-free.
WARNING: CPU: 23 PID: 5399 at lib/refcount.c:28 refcount_warn_saturate+0xa6/0xf0
A user after-free vulnerability was found in the Linux kernel in the refcount_t variable when performing the controller reset. This issue could lead to denial of service of the system.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2022-48695: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3s...
vendor_debian·2022·CVSS 7.8
CVE-2022-48695 [HIGH] CVE-2022-48695: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3s...
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix use-after-free warning Fix the following use-after-free warning which is observed during controller reset: refcount_t: underflow; use-after-free. WARNING: CPU: 23 PID: 5399 at lib/refcount.c:28 refcount_warn_saturate+0xa6/0xf0
Scope: local
bookworm: resolved (fixed in 5.19.11-1)
bullseye: resolved (fixed in 5.10.148-1)
forky: resolved (fixed in 5.19.11-1)
sid: resolved (fixed in 5.19.11-1)
trixie: resolved (fixed in 5.19.11-1)
OSV
CVE-2022-48695: In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix use-after-free warning Fix the following use-after-free warning
osv·2024-05-03·CVSS 7.8
CVE-2022-48695 [HIGH] CVE-2022-48695: In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix use-after-free warning Fix the following use-after-free warning
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix use-after-free warning Fix the following use-after-free warning which is observed during controller reset: refcount_t: underflow; use-after-free. WARNING: CPU: 23 PID: 5399 at lib/refcount.c:28 refcount_warn_saturate+0xa6/0xf0
GHSA
GHSA-jvc3-6gh7-chwx: In the Linux kernel, the following vulnerability has been resolved:
scsi: mpt3sas: Fix use-after-free warning
Fix the following use-after-free warni
ghsa_unreviewed·2024-05-03
CVE-2022-48695 [HIGH] CWE-416 GHSA-jvc3-6gh7-chwx: In the Linux kernel, the following vulnerability has been resolved:
scsi: mpt3sas: Fix use-after-free warning
Fix the following use-after-free warni
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpt3sas: Fix use-after-free warning
Fix the following use-after-free warning which is observed during
controller reset:
refcount_t: underflow; use-after-free.
WARNING: CPU: 23 PID: 5399 at lib/refcount.c:28 refcount_warn_saturate+0xa6/0xf0
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/41acb064c4e013808bc7d5fc1b506fa449425b0bhttps://git.kernel.org/stable/c/5682c94644fde72f72bded6580c38189ffc856b5https://git.kernel.org/stable/c/6229fa494a5949be209bc73afbc5d0a749c2e3c7https://git.kernel.org/stable/c/82efb917eeb27454dc4c6fe26432fc8f6c75bc16https://git.kernel.org/stable/c/991df3dd5144f2e6b1c38b8d20ed3d4d21e20b34https://git.kernel.org/stable/c/b8fc9e91b931215110ba824d1a2983c5f60b6f82https://git.kernel.org/stable/c/d4959d09b76eb7a4146f5133962b88d3bddb63d6https://git.kernel.org/stable/c/ea10a652ad2ae2cf3eced6f632a5c98f26727057https://git.kernel.org/stable/c/41acb064c4e013808bc7d5fc1b506fa449425b0bhttps://git.kernel.org/stable/c/5682c94644fde72f72bded6580c38189ffc856b5https://git.kernel.org/stable/c/6229fa494a5949be209bc73afbc5d0a749c2e3c7https://git.kernel.org/stable/c/82efb917eeb27454dc4c6fe26432fc8f6c75bc16https://git.kernel.org/stable/c/991df3dd5144f2e6b1c38b8d20ed3d4d21e20b34https://git.kernel.org/stable/c/b8fc9e91b931215110ba824d1a2983c5f60b6f82https://git.kernel.org/stable/c/d4959d09b76eb7a4146f5133962b88d3bddb63d6https://git.kernel.org/stable/c/ea10a652ad2ae2cf3eced6f632a5c98f26727057
2024-05-03
Published