CVE-2022-48754
published 2024-06-20CVE-2022-48754: In the Linux kernel, the following vulnerability has been resolved: phylib: fix potential use-after-free Commit bafbdd527d56 ("phylib: Add device reset GPIO…
PriorityP338high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.23%
14.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
phylib: fix potential use-after-free
Commit bafbdd527d56 ("phylib: Add device reset GPIO support") added call
to phy_device_reset(phydev) after the put_device() call in phy_detach().
The comment before the put_device() call says that the phydev might go
away with put_device().
Fix potential use-after-free by calling phy_device_reset() before
put_device().
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.7-1 (bookworm) | linux 5.16.7-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= bafbdd527d569c8200521f2f7579f65a044271be < 67d271760b037ce0806d687ee6057edc8afd4205 | 67d271760b037ce0806d687ee6057edc8afd4205 |
| linux | linux | >= bafbdd527d569c8200521f2f7579f65a044271be < f39027cbada43b33566c312e6be3db654ca3ad17 | f39027cbada43b33566c312e6be3db654ca3ad17 |
| linux | linux | >= bafbdd527d569c8200521f2f7579f65a044271be < bd024e36f68174b1793906c39ca16cee0c9295c2 | bd024e36f68174b1793906c39ca16cee0c9295c2 |
| linux | linux | >= bafbdd527d569c8200521f2f7579f65a044271be < aefaccd19379d6c4620269a162bfb88ff687f289 | aefaccd19379d6c4620269a162bfb88ff687f289 |
| linux | linux | >= bafbdd527d569c8200521f2f7579f65a044271be < cb2fab10fc5e7a3aa1bb0a68a3abdcf3e37852af | cb2fab10fc5e7a3aa1bb0a68a3abdcf3e37852af |
| linux | linux | >= bafbdd527d569c8200521f2f7579f65a044271be < cbda1b16687580d5beee38273f6241ae3725960c | cbda1b16687580d5beee38273f6241ae3725960c |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.103-1 | 5.10.103-1 |
| linux | linux_kernel | >= 0 < 5.16.7-1 | 5.16.7-1 |
| linux | linux_kernel | >= 0 < 5.16.7-1 | 5.16.7-1 |
| linux | linux_kernel | >= 0 < 5.16.7-1 | 5.16.7-1 |
| linux | linux_kernel | >= 4.16 < 4.19.228 | 4.19.228 |
| linux | linux_kernel | >= 4.20 < 5.4.176 | 5.4.176 |
| linux | linux_kernel | >= 5.11 < 5.15.19 | 5.15.19 |
| linux | linux_kernel | >= 5.16 < 5.16.5 | 5.16.5 |
| linux | linux_kernel | >= 5.5 < 5.10.96 | 5.10.96 |
CVSS provenance
nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.4HIGH
vendor_debian8.4HIGH
vendor_redhat8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-48754: In the Linux kernel, the following vulnerability has been resolved: phylib: fix potential use-after-free Commit bafbdd527d56 ("phylib: Add device rese
osv·2024-06-20·CVSS 8.4
CVE-2022-48754 [HIGH] CVE-2022-48754: In the Linux kernel, the following vulnerability has been resolved: phylib: fix potential use-after-free Commit bafbdd527d56 ("phylib: Add device rese
In the Linux kernel, the following vulnerability has been resolved: phylib: fix potential use-after-free Commit bafbdd527d56 ("phylib: Add device reset GPIO support") added call to phy_device_reset(phydev) after the put_device() call in phy_detach(). The comment before the put_device() call says that the phydev might go away with put_device(). Fix potential use-after-free by calling phy_device_reset() before put_device().
GHSA
GHSA-9wpf-m764-qmf8: In the Linux kernel, the following vulnerability has been resolved:
phylib: fix potential use-after-free
Commit bafbdd527d56 ("phylib: Add device re
ghsa_unreviewed·2024-06-20
CVE-2022-48754 [HIGH] CWE-416 GHSA-9wpf-m764-qmf8: In the Linux kernel, the following vulnerability has been resolved:
phylib: fix potential use-after-free
Commit bafbdd527d56 ("phylib: Add device re
In the Linux kernel, the following vulnerability has been resolved:
phylib: fix potential use-after-free
Commit bafbdd527d56 ("phylib: Add device reset GPIO support") added call
to phy_device_reset(phydev) after the put_device() call in phy_detach().
The comment before the put_device() call says that the phydev might go
away with put_device().
Fix potential use-after-free by calling phy_device_reset() before
put_device().
Red Hat
kernel: phylib: fix potential use-after-free
vendor_redhat·2024-06-20·CVSS 8.4
CVE-2022-48754 [HIGH] CWE-416 kernel: phylib: fix potential use-after-free
kernel: phylib: fix potential use-after-free
In the Linux kernel, the following vulnerability has been resolved:
phylib: fix potential use-after-free
Commit bafbdd527d56 ("phylib: Add device reset GPIO support") added call
to phy_device_reset(phydev) after the put_device() call in phy_detach().
The comment before the put_device() call says that the phydev might go
away with put_device().
Fix potential use-after-free by calling phy_device_reset() before
put_device().
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 9) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Affected
Debian
CVE-2022-48754: linux - In the Linux kernel, the following vulnerability has been resolved: phylib: fix...
vendor_debian·2022·CVSS 8.4
CVE-2022-48754 [HIGH] CVE-2022-48754: linux - In the Linux kernel, the following vulnerability has been resolved: phylib: fix...
In the Linux kernel, the following vulnerability has been resolved: phylib: fix potential use-after-free Commit bafbdd527d56 ("phylib: Add device reset GPIO support") added call to phy_device_reset(phydev) after the put_device() call in phy_detach(). The comment before the put_device() call says that the phydev might go away with put_device(). Fix potential use-after-free by calling phy_device_reset() before put_device().
Scope: local
bookworm: resolved (fixed in 5.16.7-1)
bullseye: resolved (fixed in 5.10.103-1)
forky: resolved (fixed in 5.16.7-1)
sid: resolved (fixed in 5.16.7-1)
trixie: resolved (fixed in 5.16.7-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/67d271760b037ce0806d687ee6057edc8afd4205https://git.kernel.org/stable/c/aefaccd19379d6c4620269a162bfb88ff687f289https://git.kernel.org/stable/c/bd024e36f68174b1793906c39ca16cee0c9295c2https://git.kernel.org/stable/c/cb2fab10fc5e7a3aa1bb0a68a3abdcf3e37852afhttps://git.kernel.org/stable/c/cbda1b16687580d5beee38273f6241ae3725960chttps://git.kernel.org/stable/c/f39027cbada43b33566c312e6be3db654ca3ad17https://git.kernel.org/stable/c/67d271760b037ce0806d687ee6057edc8afd4205https://git.kernel.org/stable/c/aefaccd19379d6c4620269a162bfb88ff687f289https://git.kernel.org/stable/c/bd024e36f68174b1793906c39ca16cee0c9295c2https://git.kernel.org/stable/c/cb2fab10fc5e7a3aa1bb0a68a3abdcf3e37852afhttps://git.kernel.org/stable/c/cbda1b16687580d5beee38273f6241ae3725960chttps://git.kernel.org/stable/c/f39027cbada43b33566c312e6be3db654ca3ad17
2024-06-20
Published