CVE-2022-48958
published 2024-10-21CVE-2022-48958: In the Linux kernel, the following vulnerability has been resolved: ethernet: aeroflex: fix potential skb leak in greth_init_rings() The greth_init_rings()…
PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
ethernet: aeroflex: fix potential skb leak in greth_init_rings()
The greth_init_rings() function won't free the newly allocated skb when
dma_mapping_error() returns error, so add dev_kfree_skb() to fix it.
Compile tested only.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| libarchive | libarchive | >= 0 < 3.4.0-2ubuntu1.3 | 3.4.0-2ubuntu1.3 |
| libarchive | libarchive | >= 0 < 3.6.0-1ubuntu1.2 | 3.6.0-1ubuntu1.2 |
| libarchive | libarchive | >= 0 < 3.7.2-2ubuntu0.2 | 3.7.2-2ubuntu0.2 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.8+esm3 | 3.1.2-7ubuntu2.8+esm3 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.8+esm1 | 3.1.2-11ubuntu0.16.04.8+esm1 |
| libarchive | libarchive | >= 0 < 3.2.2-3.1ubuntu0.7+esm1 | 3.2.2-3.1ubuntu0.7+esm1 |
| linux | linux | — | — |
| linux | linux | >= d4c41139df6e74c6fff0cbac43e51cab782133be < 223654e2e2c8d05347cd8e300f8d1ec6023103dd | 223654e2e2c8d05347cd8e300f8d1ec6023103dd |
| linux | linux | >= d4c41139df6e74c6fff0cbac43e51cab782133be < cb1e293f858e5e1152b8791047ed4bdaaf392189 | cb1e293f858e5e1152b8791047ed4bdaaf392189 |
| linux | linux | >= d4c41139df6e74c6fff0cbac43e51cab782133be < bfaa8f6c5b84b295dd73b0138b57c5555ca12b1c | bfaa8f6c5b84b295dd73b0138b57c5555ca12b1c |
| linux | linux | >= d4c41139df6e74c6fff0cbac43e51cab782133be < 99669d94ce145389f1d6f197e6e18ed50d43fb76 | 99669d94ce145389f1d6f197e6e18ed50d43fb76 |
| linux | linux | >= d4c41139df6e74c6fff0cbac43e51cab782133be < 87277bdf2c370ab2d07cfe77dfa9b37f82bbe1e5 | 87277bdf2c370ab2d07cfe77dfa9b37f82bbe1e5 |
| linux | linux | >= d4c41139df6e74c6fff0cbac43e51cab782133be < c7adcbd0fd3fde1b19150c3e955fb4a30c5bd9b7 | c7adcbd0fd3fde1b19150c3e955fb4a30c5bd9b7 |
| linux | linux | >= d4c41139df6e74c6fff0cbac43e51cab782133be < dd62867a6383f78f75f07039394aac25924a3307 | dd62867a6383f78f75f07039394aac25924a3307 |
| linux | linux | >= d4c41139df6e74c6fff0cbac43e51cab782133be < 063a932b64db3317ec020c94466fe52923a15f60 | 063a932b64db3317ec020c94466fe52923a15f60 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.162-1 | 5.10.162-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 2.6.34 < 4.9.336 | 4.9.336 |
| linux | linux_kernel | >= 4.10 < 4.14.302 | 4.14.302 |
| linux | linux_kernel | >= 4.15 < 4.19.269 | 4.19.269 |
| linux | linux_kernel | >= 4.20 < 5.4.227 | 5.4.227 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv9.8CRITICAL
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ethernet: aeroflex: fix potential skb leak in greth_init_rings()
vendor_redhat·2024-10-21·CVSS 5.5
CVE-2022-48958 [MEDIUM] CWE-772 kernel: ethernet: aeroflex: fix potential skb leak in greth_init_rings()
kernel: ethernet: aeroflex: fix potential skb leak in greth_init_rings()
In the Linux kernel, the following vulnerability has been resolved:
ethernet: aeroflex: fix potential skb leak in greth_init_rings()
The greth_init_rings() function won't free the newly allocated skb when
dma_mapping_error() returns error, so add dev_kfree_skb() to fix it.
Compile tested only.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Not affe
Debian
CVE-2022-48958: linux - In the Linux kernel, the following vulnerability has been resolved: ethernet: a...
vendor_debian·2022·CVSS 5.5
CVE-2022-48958 [MEDIUM] CVE-2022-48958: linux - In the Linux kernel, the following vulnerability has been resolved: ethernet: a...
In the Linux kernel, the following vulnerability has been resolved: ethernet: aeroflex: fix potential skb leak in greth_init_rings() The greth_init_rings() function won't free the newly allocated skb when dma_mapping_error() returns error, so add dev_kfree_skb() to fix it. Compile tested only.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.162-1)
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
GHSA
GHSA-6892-j46w-9wqm: In the Linux kernel, the following vulnerability has been resolved:
ethernet: aeroflex: fix potential skb leak in greth_init_rings()
The greth_init_
ghsa_unreviewed·2024-10-21
CVE-2022-48958 [MEDIUM] CWE-401 GHSA-6892-j46w-9wqm: In the Linux kernel, the following vulnerability has been resolved:
ethernet: aeroflex: fix potential skb leak in greth_init_rings()
The greth_init_
In the Linux kernel, the following vulnerability has been resolved:
ethernet: aeroflex: fix potential skb leak in greth_init_rings()
The greth_init_rings() function won't free the newly allocated skb when
dma_mapping_error() returns error, so add dev_kfree_skb() to fix it.
Compile tested only.
OSV
CVE-2022-48958: In the Linux kernel, the following vulnerability has been resolved: ethernet: aeroflex: fix potential skb leak in greth_init_rings() The greth_init_ri
osv·2024-10-21·CVSS 5.5
CVE-2022-48958 [MEDIUM] CVE-2022-48958: In the Linux kernel, the following vulnerability has been resolved: ethernet: aeroflex: fix potential skb leak in greth_init_rings() The greth_init_ri
In the Linux kernel, the following vulnerability has been resolved: ethernet: aeroflex: fix potential skb leak in greth_init_rings() The greth_init_rings() function won't free the newly allocated skb when dma_mapping_error() returns error, so add dev_kfree_skb() to fix it. Compile tested only.
OSV
libarchive vulnerabilities
osv·2024-10-16·CVSS 9.8
CVE-2022-36227 libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive mishandled certain memory checks,
which could result in a NULL pointer dereference. An attacker could
potentially use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-36227)
It was discovered that libarchive mishandled certain memory operations,
which could result in an out-of-bounds memory access. An attacker could
potentially use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.
(CVE-2024-48957, CVE-2024-48958)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/063a932b64db3317ec020c94466fe52923a15f60https://git.kernel.org/stable/c/223654e2e2c8d05347cd8e300f8d1ec6023103ddhttps://git.kernel.org/stable/c/87277bdf2c370ab2d07cfe77dfa9b37f82bbe1e5https://git.kernel.org/stable/c/99669d94ce145389f1d6f197e6e18ed50d43fb76https://git.kernel.org/stable/c/bfaa8f6c5b84b295dd73b0138b57c5555ca12b1chttps://git.kernel.org/stable/c/c7adcbd0fd3fde1b19150c3e955fb4a30c5bd9b7https://git.kernel.org/stable/c/cb1e293f858e5e1152b8791047ed4bdaaf392189https://git.kernel.org/stable/c/dd62867a6383f78f75f07039394aac25924a3307
2024-10-21
Published