cbcvebase.
CVE-2022-48911
published 2024-08-22

CVE-2022-48911: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: fix possible use-after-free Eric Dumazet says: The sock_hold() side…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
12.0th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: fix possible use-after-free Eric Dumazet says: The sock_hold() side seems suspect, because there is no guarantee that sk_refcnt is not already 0. On failure, we cannot queue the packet and need to indicate an error. The packet will be dropped by the caller. v2: split skb prefetch hunk into separate change

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.14-1 (bookworm)linux 5.16.14-1 (bookworm)
linuxlinux
linuxlinux>= 271b72c7fa82c2c7a795bc16896149933110672d < 21b27b2baa27423286e9b8d3f0b194d587083d9521b27b2baa27423286e9b8d3f0b194d587083d95
linuxlinux>= 271b72c7fa82c2c7a795bc16896149933110672d < ef97921ccdc243170fcef857ba2a17cf697aece5ef97921ccdc243170fcef857ba2a17cf697aece5
linuxlinux>= 271b72c7fa82c2c7a795bc16896149933110672d < 34dc4a6a7f261736ef7183868a5bddad31c7f9e334dc4a6a7f261736ef7183868a5bddad31c7f9e3
linuxlinux>= 271b72c7fa82c2c7a795bc16896149933110672d < 43c25da41e3091b31a906651a43e80a2719aa1ff43c25da41e3091b31a906651a43e80a2719aa1ff
linuxlinux>= 271b72c7fa82c2c7a795bc16896149933110672d < 4d05239203fa38ea8a6f31e228460da4cb17a71a4d05239203fa38ea8a6f31e228460da4cb17a71a
linuxlinux>= 271b72c7fa82c2c7a795bc16896149933110672d < dd648bd1b33a828f62befa696b206c688da0ec43dd648bd1b33a828f62befa696b206c688da0ec43
linuxlinux>= 271b72c7fa82c2c7a795bc16896149933110672d < dcc3cb920bf7ba66ac5e9272293a9ba5f80917eedcc3cb920bf7ba66ac5e9272293a9ba5f80917ee
linuxlinux>= 271b72c7fa82c2c7a795bc16896149933110672d < c3873070247d9e3c7a6b0cf9bf9b45e8018427b1c3873070247d9e3c7a6b0cf9bf9b45e8018427b1
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.106-15.10.106-1
linuxlinux_kernel>= 0 < 5.16.14-15.16.14-1
linuxlinux_kernel>= 0 < 5.16.14-15.16.14-1
linuxlinux_kernel>= 0 < 5.16.14-15.16.14-1
linuxlinux_kernel>= 2.6.29 < 4.9.3054.9.305
linuxlinux_kernel>= 4.10 < 4.14.2704.14.270
linuxlinux_kernel>= 4.15 < 4.19.2334.19.233
linuxlinux_kernel>= 4.20 < 5.4.1835.4.183
linuxlinux_kernel>= 5.11 < 5.15.275.15.27

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.