CVE-2022-48957
published 2024-10-21CVE-2022-48957: In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and…
PriorityP415medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove()
The cmd_buff needs to be freed when error happened in
dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove().
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| libarchive | libarchive | >= 0 < 3.4.0-2ubuntu1.3 | 3.4.0-2ubuntu1.3 |
| libarchive | libarchive | >= 0 < 3.6.0-1ubuntu1.2 | 3.6.0-1ubuntu1.2 |
| libarchive | libarchive | >= 0 < 3.7.2-2ubuntu0.2 | 3.7.2-2ubuntu0.2 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.8+esm3 | 3.1.2-7ubuntu2.8+esm3 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.8+esm1 | 3.1.2-11ubuntu0.16.04.8+esm1 |
| libarchive | libarchive | >= 0 < 3.2.2-3.1ubuntu0.7+esm1 | 3.2.2-3.1ubuntu0.7+esm1 |
| linux | linux | — | — |
| linux | linux | >= 1110318d83e8011c4dfcb2f7dd343bcfb1623c5f < 54d830e24247fa8361b016dd2069362866f45cb6 | 54d830e24247fa8361b016dd2069362866f45cb6 |
| linux | linux | >= 1110318d83e8011c4dfcb2f7dd343bcfb1623c5f < 785ee7a82297e1512d9061aae91699212ed65796 | 785ee7a82297e1512d9061aae91699212ed65796 |
| linux | linux | >= 1110318d83e8011c4dfcb2f7dd343bcfb1623c5f < 4fad22a1281c500f15b172c9d261eff347ca634b | 4fad22a1281c500f15b172c9d261eff347ca634b |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 5.13 < 5.15.83 | 5.15.83 |
| linux | linux_kernel | >= 5.16 < 6.0.13 | 6.0.13 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv9.8CRITICAL
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove()
vendor_redhat·2024-10-21·CVSS 5.5
CVE-2022-48957 [MEDIUM] CWE-401 kernel: dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove()
kernel: dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove()
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove()
The cmd_buff needs to be freed when error happened in
dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove().
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterp
Debian
CVE-2022-48957: linux - In the Linux kernel, the following vulnerability has been resolved: dpaa2-switc...
vendor_debian·2022·CVSS 5.5
CVE-2022-48957 [MEDIUM] CVE-2022-48957: linux - In the Linux kernel, the following vulnerability has been resolved: dpaa2-switc...
In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove() The cmd_buff needs to be freed when error happened in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove().
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
OSV
CVE-2022-48957: In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl
osv·2024-10-21·CVSS 5.5
CVE-2022-48957 [MEDIUM] CVE-2022-48957: In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl
In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove() The cmd_buff needs to be freed when error happened in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove().
GHSA
GHSA-2fm5-x4wv-3p5g: In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_ac
ghsa_unreviewed·2024-10-21
CVE-2022-48957 [MEDIUM] CWE-401 GHSA-2fm5-x4wv-3p5g: In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_ac
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove()
The cmd_buff needs to be freed when error happened in
dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove().
OSV
libarchive vulnerabilities
osv·2024-10-16·CVSS 9.8
CVE-2022-36227 libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive mishandled certain memory checks,
which could result in a NULL pointer dereference. An attacker could
potentially use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-36227)
It was discovered that libarchive mishandled certain memory operations,
which could result in an out-of-bounds memory access. An attacker could
potentially use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.
(CVE-2024-48957, CVE-2024-48958)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-21
Published