cbcvebase.
CVE-2022-48695
published 2024-05-03

CVE-2022-48695: In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix use-after-free warning Fix the following use-after-free warning which is…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.4th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix use-after-free warning Fix the following use-after-free warning which is observed during controller reset: refcount_t: underflow; use-after-free. WARNING: CPU: 23 PID: 5399 at lib/refcount.c:28 refcount_warn_saturate+0xa6/0xf0

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.19.11-1 (bookworm)linux 5.19.11-1 (bookworm)
linuxlinux
linuxlinux>= 146b16c8071f5f6c67895d15beeee1163f5107c4 < b8fc9e91b931215110ba824d1a2983c5f60b6f82b8fc9e91b931215110ba824d1a2983c5f60b6f82
linuxlinux>= 146b16c8071f5f6c67895d15beeee1163f5107c4 < d4959d09b76eb7a4146f5133962b88d3bddb63d6d4959d09b76eb7a4146f5133962b88d3bddb63d6
linuxlinux>= 146b16c8071f5f6c67895d15beeee1163f5107c4 < 82efb917eeb27454dc4c6fe26432fc8f6c75bc1682efb917eeb27454dc4c6fe26432fc8f6c75bc16
linuxlinux>= 146b16c8071f5f6c67895d15beeee1163f5107c4 < 5682c94644fde72f72bded6580c38189ffc856b55682c94644fde72f72bded6580c38189ffc856b5
linuxlinux>= 146b16c8071f5f6c67895d15beeee1163f5107c4 < ea10a652ad2ae2cf3eced6f632a5c98f26727057ea10a652ad2ae2cf3eced6f632a5c98f26727057
linuxlinux>= 146b16c8071f5f6c67895d15beeee1163f5107c4 < 6229fa494a5949be209bc73afbc5d0a749c2e3c76229fa494a5949be209bc73afbc5d0a749c2e3c7
linuxlinux>= 146b16c8071f5f6c67895d15beeee1163f5107c4 < 41acb064c4e013808bc7d5fc1b506fa449425b0b41acb064c4e013808bc7d5fc1b506fa449425b0b
linuxlinux>= 146b16c8071f5f6c67895d15beeee1163f5107c4 < 991df3dd5144f2e6b1c38b8d20ed3d4d21e20b34991df3dd5144f2e6b1c38b8d20ed3d4d21e20b34
linuxlinux_kernel< 4.9.3284.9.328
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.148-15.10.148-1
linuxlinux_kernel>= 0 < 5.19.11-15.19.11-1
linuxlinux_kernel>= 0 < 5.19.11-15.19.11-1
linuxlinux_kernel>= 0 < 5.19.11-15.19.11-1
linuxlinux_kernel>= 4.10 < 4.14.2934.14.293
linuxlinux_kernel>= 4.15 < 4.19.2584.19.258
linuxlinux_kernel>= 4.20 < 5.4.2135.4.213
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 5.19.95.19.9
linuxlinux_kernel>= 5.5 < 5.10.1435.10.143

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.