cbcvebase.
CVE-2022-48956
published 2024-10-21

CVE-2022-48956: In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid use-after-free in ip6_fragment() Blamed commit claimed rcu_read_lock() was held…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid use-after-free in ip6_fragment() Blamed commit claimed rcu_read_lock() was held by ip6_fragment() callers. It seems to not be always true, at least for UDP stack. syzbot reported: BUG: KASAN: use-after-free in ip6_dst_idev include/net/ip6_fib.h:245 [inline] BUG: KASAN: use-after-free in ip6_fragment+0x2724/0x2770 net/ipv6/ip6_output.c:951 Read of size 8 at addr ffff88801d403e80 by task syz-executor.3/7618 CPU: 1 PID: 7618 Comm: syz-executor.3 Not tainted 6.1.0-rc6-syzkaller-00012-g4312098baf37 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022 Call Trace: __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xd1/0x138 lib/dump_stack.c:106 print_address_description mm/kasan/report.c:284 [inline] print_report+0x15e/0x45d mm/kasan/report.c:395 kasan_report+0xbf/0x1f0 mm/kasan/report.c:495 ip6_dst_idev include/net/ip6_fib.h:245 [inline] ip6_fragment+0x2724/0x2770 net/ipv6/ip6_output.c:951 __ip6_finish_output net/ipv6/ip6_output.c:193 [inline] ip6_finish_output+0x9a3/0x1170 net/ipv6/ip6_output.c:206 NF_HOOK_COND include/linux/netfilter.h:291 [inline] ip6_output+0x1f1/0x540 net/ipv6/ip6_output.c:227 dst_output include/net/dst.h:445 [inline] ip6_local_out+0xb3/0x1a0 net/ipv6/output_core.c:161 ip6_send_skb+0xbb/0x340 net/ipv6/ip6_output.c:1966 udp_v6_send_skb+0x82a/0x18a0 net/ipv6/udp.c:1286 udp_v6_push_pending_frames+0x140/0x200 net/ipv6/udp.c:1313 udpv6_sendmsg+0x18da/0x2c80 net/ipv6/udp.c:1606 inet6_sendmsg+0x9d/0xe0 net/ipv6/af_inet6.c:665 sock_sendmsg_nosec net/socket.c:714 [inline] sock_sendmsg+0xd3/0x120 net/socket.c:734 sock_write_iter+0x295/0x3d0 net/socket.c:1108 call_write_iter include/linux/fs.h:2191 [inline] new_sync_write fs/read_write.c:491 [inline] vfs_write+0x9ed/0xdd0 fs/read_write.c:584 ksys_write+0x1ec/0x250 fs/read_write.c:637 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x39/0xb0 arch/x86/entry/common.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 1758fd4688eb92c796e75bdb1d256dc558ef9581 < b3d7ff8c04a83279fb7641fc4d5aa82a602df7c0b3d7ff8c04a83279fb7641fc4d5aa82a602df7c0
linuxlinux>= 1758fd4688eb92c796e75bdb1d256dc558ef9581 < 7e0dcd5f3ade221a6126278aca60c8ab4cc3bce97e0dcd5f3ade221a6126278aca60c8ab4cc3bce9
linuxlinux>= 1758fd4688eb92c796e75bdb1d256dc558ef9581 < 6b6d3be3661bff2746cab26147bd629aa034e0946b6d3be3661bff2746cab26147bd629aa034e094
linuxlinux>= 1758fd4688eb92c796e75bdb1d256dc558ef9581 < 8208d7e56b1e579320b9ff3712739ad2e63e1f868208d7e56b1e579320b9ff3712739ad2e63e1f86
linuxlinux>= 1758fd4688eb92c796e75bdb1d256dc558ef9581 < 7390c70bd431cbfa6951477e2c80a301643e284b7390c70bd431cbfa6951477e2c80a301643e284b
linuxlinux>= 1758fd4688eb92c796e75bdb1d256dc558ef9581 < 9b1a468a455d8319041528778d0e684a4c0627929b1a468a455d8319041528778d0e684a4c062792
linuxlinux>= 1758fd4688eb92c796e75bdb1d256dc558ef9581 < 803e84867de59a1e5d126666d25eb4860cfd2ebe803e84867de59a1e5d126666d25eb4860cfd2ebe
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.162-15.10.162-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.13 < 4.14.3024.14.302
linuxlinux_kernel>= 4.15 < 4.19.2694.19.269
linuxlinux_kernel>= 4.20 < 5.4.2275.4.227
linuxlinux_kernel>= 5.11 < 5.15.835.15.83
linuxlinux_kernel>= 5.16 < 6.0.136.0.13
linuxlinux_kernel>= 5.5 < 5.10.1595.10.159

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.