Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-48659— mm/slub: fix to return errno if kmalloc() fails

AI Predicted 5.3 Difficulty: Trivial EPSS 0.24% · P16

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinux81819f0fc8285a2a5a921c019e3e3d7b6169d225< e9219fa63c5c25804af82c7aa54d1ec770ebe457affected
81819f0fc8285a2a5a921c019e3e3d7b6169d225< a1d83a19cec3bfeb2b3547a1f7631e432a766d1caffected
81819f0fc8285a2a5a921c019e3e3d7b6169d225< e996821717c5cf8aa1e1abdb6b3d900a231e3755affected
81819f0fc8285a2a5a921c019e3e3d7b6169d225< 016b150992eebc32c4a18f783cf2bb6e2545a3d9affected
81819f0fc8285a2a5a921c019e3e3d7b6169d225< 379ac7905ff3f0a6a4e507d3e9f710ec4fab9124affected
81819f0fc8285a2a5a921c019e3e3d7b6169d225< 2d6e55e0c03804e1e227b80a5746e086d6c6696caffected
81819f0fc8285a2a5a921c019e3e3d7b6169d225< 02bcd951aa3c2cea95fb241c20802e9501940296affected
81819f0fc8285a2a5a921c019e3e3d7b6169d225< 7e9c323c52b379d261a72dc7bd38120a761a93cdaffected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-48659

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mm/slub: fix to return errno if kmalloc() fails
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mm/slub: fix to return errno if kmalloc() fails In create_unique_id(), kmalloc(, GFP_KERNEL) can fail due to out-of-memory, if it fails, return errno correctly rather than triggering panic via BUG_ON(); kernel BUG at mm/slub.c:5893! Internal error: Oops - BUG: 0 [#1] PREEMPT SMP Call trace: sysfs_slab_add+0x258/0x260 mm/slub.c:5973 __kmem_cache_create+0x60/0x118 mm/slub.c:4899 create_cache mm/slab_common.c:229 [inline] kmem_cache_create_usercopy+0x19c/0x31c mm/slab_common.c:335 kmem_cache_create+0x1c/0x28 mm/slab_common.c:390 f2fs_kmem_cache_create fs/f2fs/f2fs.h:2766 [inline] f2fs_init_xattr_caches+0x78/0xb4 fs/f2fs/xattr.c:808 f2fs_fill_super+0x1050/0x1e0c fs/f2fs/super.c:4149 mount_bdev+0x1b8/0x210 fs/super.c:1400 f2fs_mount+0x44/0x58 fs/f2fs/super.c:4512 legacy_get_tree+0x30/0x74 fs/fs_context.c:610 vfs_get_tree+0x40/0x140 fs/super.c:1530 do_new_mount+0x1dc/0x4e4 fs/namespace.c:3040 path_mount+0x358/0x914 fs/namespace.c:3370 do_mount fs/namespace.c:3383 [inline] __do_sys_mount fs/namespace.c:3591 [inline] __se_sys_mount fs/namespace.c:3568 [inline] __arm64_sys_mount+0x2f8/0x408 fs/namespace.c:3568
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于当kmalloc() 失败则返回 errno,会导致内存不足。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 81819f0fc8285a2a5a921c019e3e3d7b6169d225 ~ e9219fa63c5c25804af82c7aa54d1ec770ebe457 -
LinuxLinux 2.6.22 -

II. Public POCs for CVE-2022-48659

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-48659

登录查看更多情报信息。

Other References for CVE-2022-48659 (8)

Same Patch Batch · Linux · 2024-04-28 · 40 CVEs total

CVE-2022-486669.8 CRITICALscsi: core: Fix a use-after-free
CVE-2022-486528.8 HIGHice: Fix crash by keep old cfg when update TCs more than queues
CVE-2022-486327.8 HIGHi2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()
CVE-2022-486367.8 HIGHs390/dasd: fix Oops in dasd_alias_get_start_dev due to missing pavgroup
CVE-2022-486377.8 HIGHbnxt: prevent skb UAF after handing over to PTP worker
CVE-2022-486587.5 HIGHmm: slub: fix flush_cpu_slab()/__free_slab() invocations in task context.
CVE-2022-486657.1 HIGHexfat: fix overflow for large capacity partition
CVE-2022-486547.1 HIGHnetfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find()
CVE-2022-48644net/sched: taprio: avoid disabling offload when it was never enabled
CVE-2022-48648sfc: fix null pointer dereference in efx_hard_start_xmit
CVE-2022-48643netfilter: nf_tables: fix nft_counters_enabled underflow at nf_tables_addchain()
CVE-2022-48642netfilter: nf_tables: fix percpu memory leak at nf_tables_addchain()
CVE-2022-48641netfilter: ebtables: fix memory leak when blob is malformed
CVE-2022-48640bonding: fix NULL deref in bond_rr_gen_slave_id
CVE-2022-48639net: sched: fix possible refcount leak in tc_new_tfilter()
CVE-2022-48638cgroup: cgroup_get_from_id() must check the looked-up kn is a directory
CVE-2022-48635fsdax: Fix infinite loop in dax_iomap_rw()
CVE-2022-48634drm/gma500: Fix BUG: sleeping function called from invalid context errors
CVE-2022-48633drm/gma500: Fix WARN_ON(lock->magic != lock) error
CVE-2022-48631ext4: fix bug in extents parsing when eh_entries == 0 and eh_depth > 0

Showing top 20 of 40 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-48659

No comments yet


Leave a comment