cbcvebase.
CVE-2022-48958
published 2024-10-21

CVE-2022-48958: In the Linux kernel, the following vulnerability has been resolved: ethernet: aeroflex: fix potential skb leak in greth_init_rings() The greth_init_rings()…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ethernet: aeroflex: fix potential skb leak in greth_init_rings() The greth_init_rings() function won't free the newly allocated skb when dma_mapping_error() returns error, so add dev_kfree_skb() to fix it. Compile tested only.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
libarchivelibarchive>= 0 < 3.4.0-2ubuntu1.33.4.0-2ubuntu1.3
libarchivelibarchive>= 0 < 3.6.0-1ubuntu1.23.6.0-1ubuntu1.2
libarchivelibarchive>= 0 < 3.7.2-2ubuntu0.23.7.2-2ubuntu0.2
libarchivelibarchive>= 0 < 3.1.2-7ubuntu2.8+esm33.1.2-7ubuntu2.8+esm3
libarchivelibarchive>= 0 < 3.1.2-11ubuntu0.16.04.8+esm13.1.2-11ubuntu0.16.04.8+esm1
libarchivelibarchive>= 0 < 3.2.2-3.1ubuntu0.7+esm13.2.2-3.1ubuntu0.7+esm1
linuxlinux
linuxlinux>= d4c41139df6e74c6fff0cbac43e51cab782133be < 223654e2e2c8d05347cd8e300f8d1ec6023103dd223654e2e2c8d05347cd8e300f8d1ec6023103dd
linuxlinux>= d4c41139df6e74c6fff0cbac43e51cab782133be < cb1e293f858e5e1152b8791047ed4bdaaf392189cb1e293f858e5e1152b8791047ed4bdaaf392189
linuxlinux>= d4c41139df6e74c6fff0cbac43e51cab782133be < bfaa8f6c5b84b295dd73b0138b57c5555ca12b1cbfaa8f6c5b84b295dd73b0138b57c5555ca12b1c
linuxlinux>= d4c41139df6e74c6fff0cbac43e51cab782133be < 99669d94ce145389f1d6f197e6e18ed50d43fb7699669d94ce145389f1d6f197e6e18ed50d43fb76
linuxlinux>= d4c41139df6e74c6fff0cbac43e51cab782133be < 87277bdf2c370ab2d07cfe77dfa9b37f82bbe1e587277bdf2c370ab2d07cfe77dfa9b37f82bbe1e5
linuxlinux>= d4c41139df6e74c6fff0cbac43e51cab782133be < c7adcbd0fd3fde1b19150c3e955fb4a30c5bd9b7c7adcbd0fd3fde1b19150c3e955fb4a30c5bd9b7
linuxlinux>= d4c41139df6e74c6fff0cbac43e51cab782133be < dd62867a6383f78f75f07039394aac25924a3307dd62867a6383f78f75f07039394aac25924a3307
linuxlinux>= d4c41139df6e74c6fff0cbac43e51cab782133be < 063a932b64db3317ec020c94466fe52923a15f60063a932b64db3317ec020c94466fe52923a15f60
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.162-15.10.162-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 2.6.34 < 4.9.3364.9.336
linuxlinux_kernel>= 4.10 < 4.14.3024.14.302
linuxlinux_kernel>= 4.15 < 4.19.2694.19.269
linuxlinux_kernel>= 4.20 < 5.4.2275.4.227

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv9.8CRITICAL
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.