cbcvebase.
CVE-2022-48740
published 2024-06-20

CVE-2022-48740: In the Linux kernel, the following vulnerability has been resolved: selinux: fix double free of cond_list on error paths On error path from cond_read_list()…

PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved: selinux: fix double free of cond_list on error paths On error path from cond_read_list() and duplicate_policydb_cond_list() the cond_list_destroy() gets called a second time in caller functions, resulting in NULL pointer deref. Fix this by resetting the cond_list_len to 0 in cond_list_destroy(), making subsequent calls a noop. Also consistently reset the cond_list pointer to NULL after freeing. [PM: fix line lengths in the description]

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.10-1 (bookworm)linux 5.16.10-1 (bookworm)
linuxlinux
linuxlinux>= 60abd3181db29ea81742106cc0ac2e27fd05b418 < f446089a268c8fc6908488e991d28a9b936293dbf446089a268c8fc6908488e991d28a9b936293db
linuxlinux>= 60abd3181db29ea81742106cc0ac2e27fd05b418 < 70caa32e6d81f45f0702070c0e4dfe945e92fbd770caa32e6d81f45f0702070c0e4dfe945e92fbd7
linuxlinux>= 60abd3181db29ea81742106cc0ac2e27fd05b418 < 7ed9cbf7ac0d4ed86b356e1b944304ae9ee450d47ed9cbf7ac0d4ed86b356e1b944304ae9ee450d4
linuxlinux>= 60abd3181db29ea81742106cc0ac2e27fd05b418 < 186edf7e368c40d06cf727a1ad14698ea67b74ad186edf7e368c40d06cf727a1ad14698ea67b74ad
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.103-15.10.103-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 0 < 5.16.10-15.16.10-1
linuxlinux_kernel>= 5.11 < 5.15.225.15.22
linuxlinux_kernel>= 5.16 < 5.16.85.16.8
linuxlinux_kernel>= 5.7 < 5.10.995.10.99

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.