CVE-2022-48748
published 2024-06-20CVE-2022-48748: In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state, if vlan…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.13%
63.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: vlan: fix memory leak in __allowed_ingress
When using per-vlan state, if vlan snooping and stats are disabled,
untagged or priority-tagged ingress frame will go to check pvid state.
If the port state is forwarding and the pvid state is not
learning/forwarding, untagged or priority-tagged frame will be dropped
but skb memory is not freed.
Should free skb when __allowed_ingress returns false.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.7-1 (bookworm) | linux 5.16.7-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= a580c76d534c7360ba68042b19cb255e8420e987 < 446ff1fc37c74093e81db40811a07b5a19f1d797 | 446ff1fc37c74093e81db40811a07b5a19f1d797 |
| linux | linux | >= a580c76d534c7360ba68042b19cb255e8420e987 < c5e216e880fa6f2cd9d4a6541269377657163098 | c5e216e880fa6f2cd9d4a6541269377657163098 |
| linux | linux | >= a580c76d534c7360ba68042b19cb255e8420e987 < 14be8d448fca6fe7b2a413831eedd55aef6c6511 | 14be8d448fca6fe7b2a413831eedd55aef6c6511 |
| linux | linux | >= a580c76d534c7360ba68042b19cb255e8420e987 < fd20d9738395cf8e27d0a17eba34169699fccdff | fd20d9738395cf8e27d0a17eba34169699fccdff |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.103-1 | 5.10.103-1 |
| linux | linux_kernel | >= 0 < 5.16.7-1 | 5.16.7-1 |
| linux | linux_kernel | >= 0 < 5.16.7-1 | 5.16.7-1 |
| linux | linux_kernel | >= 0 < 5.16.7-1 | 5.16.7-1 |
| linux | linux_kernel | >= 5.11 < 5.15.19 | 5.15.19 |
| linux | linux_kernel | >= 5.16 < 5.16.5 | 5.16.5 |
| linux | linux_kernel | >= 5.6 < 5.10.96 | 5.10.96 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h9h2-6w4q-6c52: In the Linux kernel, the following vulnerability has been resolved:
net: bridge: vlan: fix memory leak in __allowed_ingress
When using per-vlan stat
ghsa_unreviewed·2024-06-20
CVE-2022-48748 [HIGH] CWE-400 GHSA-h9h2-6w4q-6c52: In the Linux kernel, the following vulnerability has been resolved:
net: bridge: vlan: fix memory leak in __allowed_ingress
When using per-vlan stat
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: vlan: fix memory leak in __allowed_ingress
When using per-vlan state, if vlan snooping and stats are disabled,
untagged or priority-tagged ingress frame will go to check pvid state.
If the port state is forwarding and the pvid state is not
learning/forwarding, untagged or priority-tagged frame will be dropped
but skb memory is not freed.
Should free skb when __allowed_ingress returns false.
OSV
CVE-2022-48748: In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state,
osv·2024-06-20·CVSS 7.5
CVE-2022-48748 [HIGH] CVE-2022-48748: In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state,
In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state, if vlan snooping and stats are disabled, untagged or priority-tagged ingress frame will go to check pvid state. If the port state is forwarding and the pvid state is not learning/forwarding, untagged or priority-tagged frame will be dropped but skb memory is not freed. Should free skb when __allowed_ingress returns false.
Red Hat
kernel: net: bridge: vlan: fix memory leak in __allowed_ingress
vendor_redhat·2024-06-20·CVSS 7.5
CVE-2022-48748 [HIGH] CWE-402 kernel: net: bridge: vlan: fix memory leak in __allowed_ingress
kernel: net: bridge: vlan: fix memory leak in __allowed_ingress
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: vlan: fix memory leak in __allowed_ingress
When using per-vlan state, if vlan snooping and stats are disabled,
untagged or priority-tagged ingress frame will go to check pvid state.
If the port state is forwarding and the pvid state is not
learning/forwarding, untagged or priority-tagged frame will be dropped
but skb memory is not freed.
Should free skb when __allowed_ingress returns false.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Af
Debian
CVE-2022-48748: linux - In the Linux kernel, the following vulnerability has been resolved: net: bridge...
vendor_debian·2022·CVSS 7.5
CVE-2022-48748 [HIGH] CVE-2022-48748: linux - In the Linux kernel, the following vulnerability has been resolved: net: bridge...
In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state, if vlan snooping and stats are disabled, untagged or priority-tagged ingress frame will go to check pvid state. If the port state is forwarding and the pvid state is not learning/forwarding, untagged or priority-tagged frame will be dropped but skb memory is not freed. Should free skb when __allowed_ingress returns false.
Scope: local
bookworm: resolved (fixed in 5.16.7-1)
bullseye: resolved (fixed in 5.10.103-1)
forky: resolved (fixed in 5.16.7-1)
sid: resolved (fixed in 5.16.7-1)
trixie: resolved (fixed in 5.16.7-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/14be8d448fca6fe7b2a413831eedd55aef6c6511https://git.kernel.org/stable/c/446ff1fc37c74093e81db40811a07b5a19f1d797https://git.kernel.org/stable/c/c5e216e880fa6f2cd9d4a6541269377657163098https://git.kernel.org/stable/c/fd20d9738395cf8e27d0a17eba34169699fccdffhttps://git.kernel.org/stable/c/14be8d448fca6fe7b2a413831eedd55aef6c6511https://git.kernel.org/stable/c/446ff1fc37c74093e81db40811a07b5a19f1d797https://git.kernel.org/stable/c/c5e216e880fa6f2cd9d4a6541269377657163098https://git.kernel.org/stable/c/fd20d9738395cf8e27d0a17eba34169699fccdff
2024-06-20
Published