cbcvebase.
CVE-2022-49258
published 2025-02-26

CVE-2022-49258: In the Linux kernel, the following vulnerability has been resolved: crypto: ccree - Fix use after free in cc_cipher_exit() kfree_sensitive(ctx_p->user.key)…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.5th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: ccree - Fix use after free in cc_cipher_exit() kfree_sensitive(ctx_p->user.key) will free the ctx_p->user.key. But ctx_p->user.key is still used in the next line, which will lead to a use after free. We can call kfree_sensitive() after dev_dbg() to avoid the uaf.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 63ee04c8b491ee148489347e7da9fbfd982ca2bb < c93017c8d5ebf55a4e453ac7c84cc84cf92ab570c93017c8d5ebf55a4e453ac7c84cc84cf92ab570
linuxlinux>= 63ee04c8b491ee148489347e7da9fbfd982ca2bb < 335bf1fc74f775a8255257aa3e33763f2257b676335bf1fc74f775a8255257aa3e33763f2257b676
linuxlinux>= 63ee04c8b491ee148489347e7da9fbfd982ca2bb < 25c358efee5153dfd240d4e0d3169d5bebe9cacd25c358efee5153dfd240d4e0d3169d5bebe9cacd
linuxlinux>= 63ee04c8b491ee148489347e7da9fbfd982ca2bb < cffb5382bd8d3cf21b874ab5b84bf7618932286bcffb5382bd8d3cf21b874ab5b84bf7618932286b
linuxlinux>= 63ee04c8b491ee148489347e7da9fbfd982ca2bb < 3d950c34074ed74d2713c3856ba01264523289e63d950c34074ed74d2713c3856ba01264523289e6
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 4.17 < 5.10.1105.10.110
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.