cbcvebase.
CVE-2022-48962
published 2024-10-21

CVE-2022-48962: In the Linux kernel, the following vulnerability has been resolved: net: hisilicon: Fix potential use-after-free in hisi_femac_rx() The skb is delivered to…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: net: hisilicon: Fix potential use-after-free in hisi_femac_rx() The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 542ae60af24f02e130e62cb3b7c23163a2350056 < 3501da8eb6d0f5f114a09ec953c54423f6f358853501da8eb6d0f5f114a09ec953c54423f6f35885
linuxlinux>= 542ae60af24f02e130e62cb3b7c23163a2350056 < 196e12671cb629d9f3b77b4d8bec854fc445533a196e12671cb629d9f3b77b4d8bec854fc445533a
linuxlinux>= 542ae60af24f02e130e62cb3b7c23163a2350056 < aceec8ab752428d8e151321479e82cc1a40fee2eaceec8ab752428d8e151321479e82cc1a40fee2e
linuxlinux>= 542ae60af24f02e130e62cb3b7c23163a2350056 < e71a46cc8c9ad75f3bb0e4b361e81f79c0214ccae71a46cc8c9ad75f3bb0e4b361e81f79c0214cca
linuxlinux>= 542ae60af24f02e130e62cb3b7c23163a2350056 < 296a50aa8b2982117520713edc1375777a9f8506296a50aa8b2982117520713edc1375777a9f8506
linuxlinux>= 542ae60af24f02e130e62cb3b7c23163a2350056 < 6f4798ac9c9e98f41553c4f5e6c832c8860a69426f4798ac9c9e98f41553c4f5e6c832c8860a6942
linuxlinux>= 542ae60af24f02e130e62cb3b7c23163a2350056 < 8595a2db8eb0ffcbb466eb9f4a7507a5ba06ebb98595a2db8eb0ffcbb466eb9f4a7507a5ba06ebb9
linuxlinux>= 542ae60af24f02e130e62cb3b7c23163a2350056 < 4640177049549de1a43e9bc49265f0cdfce08cfd4640177049549de1a43e9bc49265f0cdfce08cfd
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.162-15.10.162-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.10 < 4.14.3024.14.302
linuxlinux_kernel>= 4.15 < 4.19.2694.19.269
linuxlinux_kernel>= 4.20 < 5.4.2275.4.227
linuxlinux_kernel>= 4.8 < 4.9.3364.9.336
linuxlinux_kernel>= 5.11 < 5.15.835.15.83
linuxlinux_kernel>= 5.16 < 6.0.136.0.13
linuxlinux_kernel>= 5.5 < 5.10.1595.10.159

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.