Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-48639— net: sched: fix possible refcount leak in tc_new_tfilter()

AI Predicted 3.3 Difficulty: Moderate EPSS 0.23% · P14

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinux7d5509fa0d3ddfe252b4418513e493ac98de3317< 903f7d322c17d8e306d766404b4604e81653902aaffected
7d5509fa0d3ddfe252b4418513e493ac98de3317< 8844c750eeb03452e2b3319c27a526f447b82596affected
7d5509fa0d3ddfe252b4418513e493ac98de3317< f8162aed962be8fa07445b2b5928e84ab40dd8d7affected
7d5509fa0d3ddfe252b4418513e493ac98de3317< 0559d91ee3a2cd81b15ad5cd507539d6da867f88affected
7d5509fa0d3ddfe252b4418513e493ac98de3317< c2e1cfefcac35e0eea229e148c8284088ce437b5affected
5.1affected
< 5.1unaffected
5.4.215≤ 5.4.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-48639

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net: sched: fix possible refcount leak in tc_new_tfilter()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: sched: fix possible refcount leak in tc_new_tfilter() tfilter_put need to be called to put the refount got by tp->ops->get to avoid possible refcount leak when chain->tmplt_ops != NULL and chain->tmplt_ops != tp->ops.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于tc_new_tfilter函数中可能存在引用计数泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 7d5509fa0d3ddfe252b4418513e493ac98de3317 ~ 903f7d322c17d8e306d766404b4604e81653902a -
LinuxLinux 5.1 -

II. Public POCs for CVE-2022-48639

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-48639

登录查看更多情报信息。

Other References for CVE-2022-48639 (5)

Same Patch Batch · Linux · 2024-04-28 · 40 CVEs total

CVE-2022-486669.8 CRITICALscsi: core: Fix a use-after-free
CVE-2022-486528.8 HIGHice: Fix crash by keep old cfg when update TCs more than queues
CVE-2022-486327.8 HIGHi2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()
CVE-2022-486367.8 HIGHs390/dasd: fix Oops in dasd_alias_get_start_dev due to missing pavgroup
CVE-2022-486377.8 HIGHbnxt: prevent skb UAF after handing over to PTP worker
CVE-2022-486587.5 HIGHmm: slub: fix flush_cpu_slab()/__free_slab() invocations in task context.
CVE-2022-486657.1 HIGHexfat: fix overflow for large capacity partition
CVE-2022-486547.1 HIGHnetfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find()
CVE-2022-48645net: enetc: deny offload of tc-based TSN features on VF interfaces
CVE-2022-48649mm/slab_common: fix possible double free of kmem_cache
CVE-2022-48644net/sched: taprio: avoid disabling offload when it was never enabled
CVE-2022-48643netfilter: nf_tables: fix nft_counters_enabled underflow at nf_tables_addchain()
CVE-2022-48642netfilter: nf_tables: fix percpu memory leak at nf_tables_addchain()
CVE-2022-48641netfilter: ebtables: fix memory leak when blob is malformed
CVE-2022-48640bonding: fix NULL deref in bond_rr_gen_slave_id
CVE-2022-48638cgroup: cgroup_get_from_id() must check the looked-up kn is a directory
CVE-2022-48635fsdax: Fix infinite loop in dax_iomap_rw()
CVE-2022-48634drm/gma500: Fix BUG: sleeping function called from invalid context errors
CVE-2022-48633drm/gma500: Fix WARN_ON(lock->magic != lock) error
CVE-2022-48631ext4: fix bug in extents parsing when eh_entries == 0 and eh_depth > 0

Showing top 20 of 40 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-48639

No comments yet


Leave a comment