CVE-2022-48911
published 2024-08-22CVE-2022-48911: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: fix possible use-after-free Eric Dumazet says: The sock_hold() side…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
12.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_queue: fix possible use-after-free
Eric Dumazet says:
The sock_hold() side seems suspect, because there is no guarantee
that sk_refcnt is not already 0.
On failure, we cannot queue the packet and need to indicate an
error. The packet will be dropped by the caller.
v2: split skb prefetch hunk into separate change
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.14-1 (bookworm) | linux 5.16.14-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 271b72c7fa82c2c7a795bc16896149933110672d < 21b27b2baa27423286e9b8d3f0b194d587083d95 | 21b27b2baa27423286e9b8d3f0b194d587083d95 |
| linux | linux | >= 271b72c7fa82c2c7a795bc16896149933110672d < ef97921ccdc243170fcef857ba2a17cf697aece5 | ef97921ccdc243170fcef857ba2a17cf697aece5 |
| linux | linux | >= 271b72c7fa82c2c7a795bc16896149933110672d < 34dc4a6a7f261736ef7183868a5bddad31c7f9e3 | 34dc4a6a7f261736ef7183868a5bddad31c7f9e3 |
| linux | linux | >= 271b72c7fa82c2c7a795bc16896149933110672d < 43c25da41e3091b31a906651a43e80a2719aa1ff | 43c25da41e3091b31a906651a43e80a2719aa1ff |
| linux | linux | >= 271b72c7fa82c2c7a795bc16896149933110672d < 4d05239203fa38ea8a6f31e228460da4cb17a71a | 4d05239203fa38ea8a6f31e228460da4cb17a71a |
| linux | linux | >= 271b72c7fa82c2c7a795bc16896149933110672d < dd648bd1b33a828f62befa696b206c688da0ec43 | dd648bd1b33a828f62befa696b206c688da0ec43 |
| linux | linux | >= 271b72c7fa82c2c7a795bc16896149933110672d < dcc3cb920bf7ba66ac5e9272293a9ba5f80917ee | dcc3cb920bf7ba66ac5e9272293a9ba5f80917ee |
| linux | linux | >= 271b72c7fa82c2c7a795bc16896149933110672d < c3873070247d9e3c7a6b0cf9bf9b45e8018427b1 | c3873070247d9e3c7a6b0cf9bf9b45e8018427b1 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.106-1 | 5.10.106-1 |
| linux | linux_kernel | >= 0 < 5.16.14-1 | 5.16.14-1 |
| linux | linux_kernel | >= 0 < 5.16.14-1 | 5.16.14-1 |
| linux | linux_kernel | >= 0 < 5.16.14-1 | 5.16.14-1 |
| linux | linux_kernel | >= 2.6.29 < 4.9.305 | 4.9.305 |
| linux | linux_kernel | >= 4.10 < 4.14.270 | 4.14.270 |
| linux | linux_kernel | >= 4.15 < 4.19.233 | 4.19.233 |
| linux | linux_kernel | >= 4.20 < 5.4.183 | 5.4.183 |
| linux | linux_kernel | >= 5.11 < 5.15.27 | 5.15.27 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: netfilter: netfilter: nf_queue: fix possible use-after-free
vendor_redhat·2024-08-22·CVSS 5.5
CVE-2022-48911 [MEDIUM] CWE-416 kernel: netfilter: netfilter: nf_queue: fix possible use-after-free
kernel: netfilter: netfilter: nf_queue: fix possible use-after-free
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_queue: fix possible use-after-free
Eric Dumazet says:
The sock_hold() side seems suspect, because there is no guarantee
that sk_refcnt is not already 0.
On failure, we cannot queue the packet and need to indicate an
error. The packet will be dropped by the caller.
v2: split skb prefetch hunk into separate change
A use-after-free flaw was found in the Linux kernel's NetFilter functionality. This issue could allow a local user to crash the system or escalate their privileges on the system.
Statement: Only Red Hat Enterprise Linux 8 is affected.
Mitigation: Mitigation for this issue is either not available or the currently available options
Debian
CVE-2022-48911: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
vendor_debian·2022·CVSS 5.5
CVE-2022-48911 [MEDIUM] CVE-2022-48911: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: fix possible use-after-free Eric Dumazet says: The sock_hold() side seems suspect, because there is no guarantee that sk_refcnt is not already 0. On failure, we cannot queue the packet and need to indicate an error. The packet will be dropped by the caller. v2: split skb prefetch hunk into separate change
Scope: local
bookworm: resolved (fixed in 5.16.14-1)
bullseye: resolved (fixed in 5.10.106-1)
forky: resolved (fixed in 5.16.14-1)
sid: resolved (fixed in 5.16.14-1)
trixie: resolved (fixed in 5.16.14-1)
OSV
CVE-2022-48911: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: fix possible use-after-free Eric Dumazet says: The sock_hold(
osv·2024-08-22·CVSS 5.5
CVE-2022-48911 [MEDIUM] CVE-2022-48911: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: fix possible use-after-free Eric Dumazet says: The sock_hold(
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: fix possible use-after-free Eric Dumazet says: The sock_hold() side seems suspect, because there is no guarantee that sk_refcnt is not already 0. On failure, we cannot queue the packet and need to indicate an error. The packet will be dropped by the caller. v2: split skb prefetch hunk into separate change
GHSA
GHSA-7vcc-f42v-gv2x: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_queue: fix possible use-after-free
Eric Dumazet says:
The sock_hol
ghsa_unreviewed·2024-08-22
CVE-2022-48911 [MEDIUM] CWE-416 GHSA-7vcc-f42v-gv2x: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_queue: fix possible use-after-free
Eric Dumazet says:
The sock_hol
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_queue: fix possible use-after-free
Eric Dumazet says:
The sock_hold() side seems suspect, because there is no guarantee
that sk_refcnt is not already 0.
On failure, we cannot queue the packet and need to indicate an
error. The packet will be dropped by the caller.
v2: split skb prefetch hunk into separate change
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/21b27b2baa27423286e9b8d3f0b194d587083d95https://git.kernel.org/stable/c/34dc4a6a7f261736ef7183868a5bddad31c7f9e3https://git.kernel.org/stable/c/43c25da41e3091b31a906651a43e80a2719aa1ffhttps://git.kernel.org/stable/c/4d05239203fa38ea8a6f31e228460da4cb17a71ahttps://git.kernel.org/stable/c/c3873070247d9e3c7a6b0cf9bf9b45e8018427b1https://git.kernel.org/stable/c/dcc3cb920bf7ba66ac5e9272293a9ba5f80917eehttps://git.kernel.org/stable/c/dd648bd1b33a828f62befa696b206c688da0ec43https://git.kernel.org/stable/c/ef97921ccdc243170fcef857ba2a17cf697aece5
2024-08-22
Published