Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-48637— bnxt: prevent skb UAF after handing over to PTP worker

CVSS 7.8 · High EPSS 0.23% · P14

Possible ATT&CK Techniques 1AI

T1211 · Exploitation for Stealth

Affected Version Matrix 8

VendorProductVersion RangeStatus
LinuxLinux83bb623c968e7351aee5111547693f95f330dc5a< 08483e4c0c83b221b8891434a04cec405dee94a6affected
83bb623c968e7351aee5111547693f95f330dc5a< 32afa1f23e42cc635ccf4c39f24514d03d1e8338affected
83bb623c968e7351aee5111547693f95f330dc5a< c31f26c8f69f776759cbbdfb38e40ea91aa0dd65affected
5.14affected
< 5.14unaffected
5.15.71≤ 5.15.*unaffected
5.19.12≤ 5.19.*unaffected
6.0≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-48637

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bnxt: prevent skb UAF after handing over to PTP worker
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bnxt: prevent skb UAF after handing over to PTP worker When reading the timestamp is required bnxt_tx_int() hands over the ownership of the completed skb to the PTP worker. The skb should not be used afterwards, as the worker may run before the rest of our code and free the skb, leading to a use-after-free. Since dev_kfree_skb_any() accepts NULL make the loss of ownership more obvious and set skb to NULL.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于内存释放后重用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 83bb623c968e7351aee5111547693f95f330dc5a ~ 08483e4c0c83b221b8891434a04cec405dee94a6 -
LinuxLinux 5.14 -

II. Public POCs for CVE-2022-48637

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-48637

登录查看更多情报信息。

Other References for CVE-2022-48637 (3)

Same Patch Batch · Linux · 2024-04-28 · 40 CVEs total

CVE-2022-486669.8 CRITICALscsi: core: Fix a use-after-free
CVE-2022-486528.8 HIGHice: Fix crash by keep old cfg when update TCs more than queues
CVE-2022-486327.8 HIGHi2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()
CVE-2022-486367.8 HIGHs390/dasd: fix Oops in dasd_alias_get_start_dev due to missing pavgroup
CVE-2022-486587.5 HIGHmm: slub: fix flush_cpu_slab()/__free_slab() invocations in task context.
CVE-2022-486657.1 HIGHexfat: fix overflow for large capacity partition
CVE-2022-486547.1 HIGHnetfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find()
CVE-2022-48645net: enetc: deny offload of tc-based TSN features on VF interfaces
CVE-2022-48649mm/slab_common: fix possible double free of kmem_cache
CVE-2022-48644net/sched: taprio: avoid disabling offload when it was never enabled
CVE-2022-48643netfilter: nf_tables: fix nft_counters_enabled underflow at nf_tables_addchain()
CVE-2022-48642netfilter: nf_tables: fix percpu memory leak at nf_tables_addchain()
CVE-2022-48641netfilter: ebtables: fix memory leak when blob is malformed
CVE-2022-48640bonding: fix NULL deref in bond_rr_gen_slave_id
CVE-2022-48639net: sched: fix possible refcount leak in tc_new_tfilter()
CVE-2022-48638cgroup: cgroup_get_from_id() must check the looked-up kn is a directory
CVE-2022-48635fsdax: Fix infinite loop in dax_iomap_rw()
CVE-2022-48634drm/gma500: Fix BUG: sleeping function called from invalid context errors
CVE-2022-48633drm/gma500: Fix WARN_ON(lock->magic != lock) error
CVE-2022-48631ext4: fix bug in extents parsing when eh_entries == 0 and eh_depth > 0

Showing top 20 of 40 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-48637

No comments yet


Leave a comment