cbcvebase.
CVE-2022-49076
published 2025-02-26

CVE-2022-49076: In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Fix use-after-free bug for mm struct Under certain conditions, such as…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
17.0th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Fix use-after-free bug for mm struct Under certain conditions, such as MPI_Abort, the hfi1 cleanup code may represent the last reference held on the task mm. hfi1_mmu_rb_unregister() then drops the last reference and the mm is freed before the final use in hfi1_release_user_pages(). A new task may allocate the mm structure while it is still being used, resulting in problems. One manifestation is corruption of the mmap_sem counter leading to a hang in down_write(). Another is corruption of an mm struct that is in use by another task.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 3d2a9d642512c21a12d19b9250e7a835dcb41a79 < 5f54364ff6cfcd14cddf5441c4a490bb28dd69f75f54364ff6cfcd14cddf5441c4a490bb28dd69f7
linuxlinux>= 3d2a9d642512c21a12d19b9250e7a835dcb41a79 < 9ca11bd8222a612de0d2f54d050bfcf61ae2883f9ca11bd8222a612de0d2f54d050bfcf61ae2883f
linuxlinux>= 3d2a9d642512c21a12d19b9250e7a835dcb41a79 < 0b7186d657ee55e2cdefae498f07d5c1961e80230b7186d657ee55e2cdefae498f07d5c1961e8023
linuxlinux>= 3d2a9d642512c21a12d19b9250e7a835dcb41a79 < 5a9a1b24ddb510715f8f621263938186579a965c5a9a1b24ddb510715f8f621263938186579a965c
linuxlinux>= 3d2a9d642512c21a12d19b9250e7a835dcb41a79 < 2bbac98d0930e8161b1957dc0ec99de39ade1b3c2bbac98d0930e8161b1957dc0ec99de39ade1b3c
linuxlinux>= 5.9.12 < 5.105.10
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 5.11 < 5.15.345.15.34
linuxlinux_kernel>= 5.16 < 5.16.205.16.20
linuxlinux_kernel>= 5.17 < 5.17.35.17.3
linuxlinux_kernel>= 5.9.12 < 5.10.1115.10.111

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.