cbcvebase.
CVE-2022-48960
published 2024-10-21

CVE-2022-48960: In the Linux kernel, the following vulnerability has been resolved: net: hisilicon: Fix potential use-after-free in hix5hd2_rx() The skb is delivered to…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net: hisilicon: Fix potential use-after-free in hix5hd2_rx() The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 57c5bc9ad7d799e9507ba6e993398d2c55f03fab < 179499e7a240b2ef590f05eb379c810c26bbc8a4179499e7a240b2ef590f05eb379c810c26bbc8a4
linuxlinux>= 57c5bc9ad7d799e9507ba6e993398d2c55f03fab < 8067cd244cea2c332f8326842fd10158fa2cb64f8067cd244cea2c332f8326842fd10158fa2cb64f
linuxlinux>= 57c5bc9ad7d799e9507ba6e993398d2c55f03fab < 3a4eddd1cb023a71df4152fcc76092953e6fe95a3a4eddd1cb023a71df4152fcc76092953e6fe95a
linuxlinux>= 57c5bc9ad7d799e9507ba6e993398d2c55f03fab < 1b6360a093ab8969c91a30bb58b753282e2ced4c1b6360a093ab8969c91a30bb58b753282e2ced4c
linuxlinux>= 57c5bc9ad7d799e9507ba6e993398d2c55f03fab < 93aaa4bb72e388f6a4887541fd3d18b84f1b5ddc93aaa4bb72e388f6a4887541fd3d18b84f1b5ddc
linuxlinux>= 57c5bc9ad7d799e9507ba6e993398d2c55f03fab < b8ce0e6f9f88a6bb49d291498377e61ea27a5387b8ce0e6f9f88a6bb49d291498377e61ea27a5387
linuxlinux>= 57c5bc9ad7d799e9507ba6e993398d2c55f03fab < b6307f7a2fc1c5407b6176f2af34a95214a8c262b6307f7a2fc1c5407b6176f2af34a95214a8c262
linuxlinux>= 57c5bc9ad7d799e9507ba6e993398d2c55f03fab < 433c07a13f59856e4585e89e86b7d4cc59348fab433c07a13f59856e4585e89e86b7d4cc59348fab
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.162-15.10.162-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 3.16 < 4.9.3364.9.336
linuxlinux_kernel>= 4.10 < 4.14.3024.14.302
linuxlinux_kernel>= 4.15 < 4.19.2694.19.269
linuxlinux_kernel>= 4.20 < 5.4.2275.4.227
linuxlinux_kernel>= 5.11 < 5.15.835.15.83
linuxlinux_kernel>= 5.16 < 6.0.136.0.13
linuxlinux_kernel>= 5.5 < 5.10.1595.10.159

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.