cbcvebase.
CVE-2022-49275
published 2025-02-26

CVE-2022-49275: In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_tx_handler(): fix use after free of skb can_put_echo_skb() will clone skb…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
19.8th percentile
In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_tx_handler(): fix use after free of skb can_put_echo_skb() will clone skb then free the skb. Move the can_put_echo_skb() for the m_can version 3.0.x directly before the start of the xmit in hardware, similar to the 3.1.x branch.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 80646733f11c2e9de3b6339f7e635047e6087280 < d93ed9aff64968f4cdad690712eb4f48ae537bded93ed9aff64968f4cdad690712eb4f48ae537bde
linuxlinux>= 80646733f11c2e9de3b6339f7e635047e6087280 < d3892a747ab16b1eb6593a19d29f62c3b3f020acd3892a747ab16b1eb6593a19d29f62c3b3f020ac
linuxlinux>= 80646733f11c2e9de3b6339f7e635047e6087280 < 7728d937ec403a1ceff9483023252d2cb8777f817728d937ec403a1ceff9483023252d2cb8777f81
linuxlinux>= 80646733f11c2e9de3b6339f7e635047e6087280 < 08d90846e438ac22dc56fc49ec0b0d195831c5ed08d90846e438ac22dc56fc49ec0b0d195831c5ed
linuxlinux>= 80646733f11c2e9de3b6339f7e635047e6087280 < 869016a2938ac44f7b2fb7fc22c89edad99eb9b3869016a2938ac44f7b2fb7fc22c89edad99eb9b3
linuxlinux>= 80646733f11c2e9de3b6339f7e635047e6087280 < f43e64076ff1b1dcb893fb77ad1204105f710a29f43e64076ff1b1dcb893fb77ad1204105f710a29
linuxlinux>= 80646733f11c2e9de3b6339f7e635047e6087280 < 4db7d6f481990dd179a9ee7126dc7aa31ea4fff34db7d6f481990dd179a9ee7126dc7aa31ea4fff3
linuxlinux>= 80646733f11c2e9de3b6339f7e635047e6087280 < 31417073493f302d26ab66b3abc098d43227b83531417073493f302d26ab66b3abc098d43227b835
linuxlinux>= 80646733f11c2e9de3b6339f7e635047e6087280 < 2e8e79c416aae1de224c0f1860f2e3350fa171f82e8e79c416aae1de224c0f1860f2e3350fa171f8
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 3.18 < 4.9.3244.9.324
linuxlinux_kernel>= 4.10 < 4.14.2894.14.289
linuxlinux_kernel>= 4.15 < 4.19.2534.19.253
linuxlinux_kernel>= 4.20 < 5.4.2075.4.207
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2
linuxlinux_kernel>= 5.5 < 5.10.1105.10.110

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.