cbcvebase.
CVE-2022-48899
published 2024-08-21

CVE-2022-48899: In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix GEM handle creation UAF Userspace can guess the handle value and try to…

PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.24%
15.9th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix GEM handle creation UAF Userspace can guess the handle value and try to race GEM object creation with handle close, resulting in a use-after-free if we dereference the object after dropping the handle's reference. For that reason, dropping the handle's reference must be done *after* we are done dereferencing the object.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.7-1 (bookworm)linux 6.1.7-1 (bookworm)
linuxlinux
linuxlinux>= 62fb7a5e10962ac6ae2a2d2dbd3aedcb2a3e3257 < 19ec87d06acfab2313ee82b2a689bf0c154e57ea19ec87d06acfab2313ee82b2a689bf0c154e57ea
linuxlinux>= 62fb7a5e10962ac6ae2a2d2dbd3aedcb2a3e3257 < d01d6d2b06c0d8390adf8f3ba08aa60b5642ef73d01d6d2b06c0d8390adf8f3ba08aa60b5642ef73
linuxlinux>= 62fb7a5e10962ac6ae2a2d2dbd3aedcb2a3e3257 < 68bcd063857075d2f9edfed6024387ac377923e268bcd063857075d2f9edfed6024387ac377923e2
linuxlinux>= 62fb7a5e10962ac6ae2a2d2dbd3aedcb2a3e3257 < 011ecdbcd520c90c344b872ca6b4821f7783b2f8011ecdbcd520c90c344b872ca6b4821f7783b2f8
linuxlinux>= 62fb7a5e10962ac6ae2a2d2dbd3aedcb2a3e3257 < adc48e5e408afbb01d261bd303fd9fbbbaa3e317adc48e5e408afbb01d261bd303fd9fbbbaa3e317
linuxlinux>= 62fb7a5e10962ac6ae2a2d2dbd3aedcb2a3e3257 < 52531258318ed59a2dc5a43df2eaf0eb1d65438e52531258318ed59a2dc5a43df2eaf0eb1d65438e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 4.4 < 4.19.2704.19.270
linuxlinux_kernel>= 5.11 < 5.15.895.15.89
linuxlinux_kernel>= 5.16 < 6.1.76.1.7
linuxlinux_kernel>= 5.5 < 5.10.1645.10.164

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.