CVE-2022-48962

HIGH EPSS 14.7%
Published Oct 21, 20241y ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Oct 21, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: net: hisilicon: Fix potential use-after-free in hisi_femac_rx() The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
14.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-416 Use After Free Memory Safety

Affected Products 15

VendorProductVersionRange
linuxlinux_kernel*≥4.8  –  <4.9.336
linuxlinux_kernel*≥4.10  –  <4.14.302
linuxlinux_kernel*≥4.15  –  <4.19.269
linuxlinux_kernel*≥4.20  –  <5.4.227
linuxlinux_kernel*≥5.5  –  <5.10.159
linuxlinux_kernel*≥5.11  –  <5.15.83
linuxlinux_kernel*≥5.16  –  <6.0.13
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any

References 8

  • git.kernel.org https://git.kernel.org/stable/c/196e12671cb629d9f3b77b4d8bec854fc445533a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/296a50aa8b2982117520713edc1375777a9f8506
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3501da8eb6d0f5f114a09ec953c54423f6f35885
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4640177049549de1a43e9bc49265f0cdfce08cfd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6f4798ac9c9e98f41553c4f5e6c832c8860a6942
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8595a2db8eb0ffcbb466eb9f4a7507a5ba06ebb9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/aceec8ab752428d8e151321479e82cc1a40fee2e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e71a46cc8c9ad75f3bb0e4b361e81f79c0214cca
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/196e12671cb629d9f3b77b4d8bec854fc445533a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/296a50aa8b2982117520713edc1375777a9f8506
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3501da8eb6d0f5f114a09ec953c54423f6f35885
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4640177049549de1a43e9bc49265f0cdfce08cfd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6f4798ac9c9e98f41553c4f5e6c832c8860a6942
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8595a2db8eb0ffcbb466eb9f4a7507a5ba06ebb9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/aceec8ab752428d8e151321479e82cc1a40fee2e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e71a46cc8c9ad75f3bb0e4b361e81f79c0214cca
    Patch