cbcvebase.
CVE-2022-49026
published 2024-10-21

CVE-2022-49026: In the Linux kernel, the following vulnerability has been resolved: e100: Fix possible use after free in e100_xmit_prepare In e100_xmit_prepare(), if we can't…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved: e100: Fix possible use after free in e100_xmit_prepare In e100_xmit_prepare(), if we can't map the skb, then return -ENOMEM, so e100_xmit_frame() will return NETDEV_TX_BUSY and the upper layer will resend the skb. But the skb is already freed, which will cause UAF bug when the upper layer resends the skb. Remove the harmful free.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.12-1 (bookworm)linux 6.0.12-1 (bookworm)
linuxlinux
linuxlinux>= 5e5d49422dfb035ca9e280cd61d434095c151272 < b775f37d943966f6f77dca402f5a9dedce502c25b775f37d943966f6f77dca402f5a9dedce502c25
linuxlinux>= 5e5d49422dfb035ca9e280cd61d434095c151272 < 9fc27d22cdb9b1fcd754599d216a8992fed280cd9fc27d22cdb9b1fcd754599d216a8992fed280cd
linuxlinux>= 5e5d49422dfb035ca9e280cd61d434095c151272 < b46f6144ab89d3d757ead940759c505091626a7db46f6144ab89d3d757ead940759c505091626a7d
linuxlinux>= 5e5d49422dfb035ca9e280cd61d434095c151272 < 45605c75c52c7ae7bfe902214343aabcfe5ba0ff45605c75c52c7ae7bfe902214343aabcfe5ba0ff
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.12-16.0.12-1
linuxlinux_kernel>= 0 < 6.0.12-16.0.12-1
linuxlinux_kernel>= 0 < 6.0.12-16.0.12-1
linuxlinux_kernel>= 0 < 4.4.0-276.3104.4.0-276.310
linuxlinux_kernel>= 0 < 4.15.0-245.2574.15.0-245.257
linuxlinux_kernel>= 0 < 5.4.0-224.2445.4.0-224.244
linuxlinux_kernel>= 4.3 < 5.10.1585.10.158
linuxlinux_kernel>= 5.11 < 5.15.825.15.82
linuxlinux_kernel>= 5.16 < 6.0.126.0.12

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.