cbcvebase.
CVE-2022-49385
published 2025-02-26

CVE-2022-49385: In the Linux kernel, the following vulnerability has been resolved: driver: base: fix UAF when driver_attach failed When driver_attach(drv); failed, the…

PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.30%
22.0th percentile
In the Linux kernel, the following vulnerability has been resolved: driver: base: fix UAF when driver_attach failed When driver_attach(drv); failed, the driver_private will be freed. But it has been added to the bus, which caused a UAF. To fix it, we need to delete it from the bus when failed.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 190888ac01d059e38ffe77a2291d44cafa9016fb < 5d709f58c743166fe1c6914b9de0ae8868600d9b5d709f58c743166fe1c6914b9de0ae8868600d9b
linuxlinux>= 190888ac01d059e38ffe77a2291d44cafa9016fb < 823f24f2e329babd0330200d0b74882516fe57f4823f24f2e329babd0330200d0b74882516fe57f4
linuxlinux>= 190888ac01d059e38ffe77a2291d44cafa9016fb < cdf1a683a01583bca4b618dd16223cbd6e462e21cdf1a683a01583bca4b618dd16223cbd6e462e21
linuxlinux>= 190888ac01d059e38ffe77a2291d44cafa9016fb < 5389101257828d1913d713d9a40acbe14f5961df5389101257828d1913d713d9a40acbe14f5961df
linuxlinux>= 190888ac01d059e38ffe77a2291d44cafa9016fb < c059665c84feab46b7173d3a1bf36c2fb7f9df86c059665c84feab46b7173d3a1bf36c2fb7f9df86
linuxlinux>= 190888ac01d059e38ffe77a2291d44cafa9016fb < 310862e574001a97ad02272bac0fd13f75f42a27310862e574001a97ad02272bac0fd13f75f42a27
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 3.9 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.475.15.47
linuxlinux_kernel>= 5.16 < 5.17.155.17.15
linuxlinux_kernel>= 5.18 < 5.18.45.18.4
linuxlinux_kernel>= 5.5 < 5.10.1225.10.122

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.