CVE-2022-49384
published 2025-02-26CVE-2022-49384: In the Linux kernel, the following vulnerability has been resolved: md: fix double free of io_acct_set bioset Now io_acct_set is alloc and free in personality…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
md: fix double free of io_acct_set bioset
Now io_acct_set is alloc and free in personality. Remove the codes that
free io_acct_set in md_free and md_stop.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.5-1 (bookworm) | linux 5.18.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 00e3d58f50a875343124bcf5a9637520a492b0d1 < 36a2fc44c574a59ee3b5e2cb327182f227b2b07e | 36a2fc44c574a59ee3b5e2cb327182f227b2b07e |
| linux | linux | >= 0c031fd37f69deb0cd8c43bbfcfccd62ebd7e952 < f99d5b5dc8a42c807b5f1176b925aa45d61962ab | f99d5b5dc8a42c807b5f1176b925aa45d61962ab |
| linux | linux | >= 0c031fd37f69deb0cd8c43bbfcfccd62ebd7e952 < ea7d7bd90079d96f9c86bdaf0b106e0cd2a70661 | ea7d7bd90079d96f9c86bdaf0b106e0cd2a70661 |
| linux | linux | >= 0c031fd37f69deb0cd8c43bbfcfccd62ebd7e952 < 42b805af102471f53e3c7867b8c2b502ea4eef7e | 42b805af102471f53e3c7867b8c2b502ea4eef7e |
| linux | linux | >= 5.15.17 < 5.15.46 | 5.15.46 |
| linux | linux | >= 5.16.3 < 5.17 | 5.17 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 5.15.17 < 5.15.46 | 5.15.46 |
| linux | linux_kernel | >= 5.16.3 < 5.17.14 | 5.17.14 |
| linux | linux_kernel | >= 5.18 < 5.18.3 | 5.18.3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5p33-cx2m-4x9v: In the Linux kernel, the following vulnerability has been resolved:
md: fix double free of io_acct_set bioset
Now io_acct_set is alloc and free in p
ghsa_unreviewed·2025-04-17
CVE-2022-49384 [HIGH] CWE-415 GHSA-5p33-cx2m-4x9v: In the Linux kernel, the following vulnerability has been resolved:
md: fix double free of io_acct_set bioset
Now io_acct_set is alloc and free in p
In the Linux kernel, the following vulnerability has been resolved:
md: fix double free of io_acct_set bioset
Now io_acct_set is alloc and free in personality. Remove the codes that
free io_acct_set in md_free and md_stop.
OSV
CVE-2022-49384: In the Linux kernel, the following vulnerability has been resolved: md: fix double free of io_acct_set bioset Now io_acct_set is alloc and free in per
osv·2025-02-26·CVSS 7.8
CVE-2022-49384 [HIGH] CVE-2022-49384: In the Linux kernel, the following vulnerability has been resolved: md: fix double free of io_acct_set bioset Now io_acct_set is alloc and free in per
In the Linux kernel, the following vulnerability has been resolved: md: fix double free of io_acct_set bioset Now io_acct_set is alloc and free in personality. Remove the codes that free io_acct_set in md_free and md_stop.
Red Hat
kernel: md: fix double free of io_acct_set bioset
vendor_redhat·2025-02-26·CVSS 7.8
CVE-2022-49384 [HIGH] CWE-415 kernel: md: fix double free of io_acct_set bioset
kernel: md: fix double free of io_acct_set bioset
In the Linux kernel, the following vulnerability has been resolved:
md: fix double free of io_acct_set bioset
Now io_acct_set is alloc and free in personality. Remove the codes that
free io_acct_set in md_free and md_stop.
A flaw was found in the MD driver, where the io_acct_set bioset was being allocated and freed within the personality module. However, additional free operations were incorrectly implemented in the md_free and md_stop functions. This redundancy led to a double-free condition, potentially causing memory corruption or system instability.
Statement: The out of box configuration of Red Hat Enterprise Linux does not allow access to md devices to non privileged users. Therefore, Red Hat Product Security has classified this bu
Debian
CVE-2022-49384: linux - In the Linux kernel, the following vulnerability has been resolved: md: fix dou...
vendor_debian·2022·CVSS 7.8
CVE-2022-49384 [HIGH] CVE-2022-49384: linux - In the Linux kernel, the following vulnerability has been resolved: md: fix dou...
In the Linux kernel, the following vulnerability has been resolved: md: fix double free of io_acct_set bioset Now io_acct_set is alloc and free in personality. Remove the codes that free io_acct_set in md_free and md_stop.
Scope: local
bookworm: resolved (fixed in 5.18.5-1)
bullseye: resolved
forky: resolved (fixed in 5.18.5-1)
sid: resolved (fixed in 5.18.5-1)
trixie: resolved (fixed in 5.18.5-1)
No detection rules found.
No public exploits indexed.
2025-02-26
Published