Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-48693— soc: brcmstb: pm-arm: Fix refcount leak and __iomem leak bugs

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于存在refcount泄漏和__iomem泄漏漏洞。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.23% · P14

Possible ATT&CK Techniques 1 AI

T1055.001 · Dynamic-link Library Injection

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux 0b741b8234c86065fb6954d32d427b3f7e14756f< 0284b4e6dec6088a41607aa3f42bf51edff01883 affected
0b741b8234c86065fb6954d32d427b3f7e14756f< 57b2897ec3ffe4cbe018446be6d04432919dca6b affected
0b741b8234c86065fb6954d32d427b3f7e14756f< 6dc0251638a4a1a998506dbd4627f8317e907558 affected
0b741b8234c86065fb6954d32d427b3f7e14756f< 43245c77d9efd8c9eb91bf225d07954dcf32204d affected
0b741b8234c86065fb6954d32d427b3f7e14756f< 653500b400d5576940b7429690f7197199ddcc82 affected
0b741b8234c86065fb6954d32d427b3f7e14756f< 1085f5080647f0c9f357c270a537869191f7f2a1 affected
4.15 affected
< 4.15 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-48693

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
soc: brcmstb: pm-arm: Fix refcount leak and __iomem leak bugs
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: soc: brcmstb: pm-arm: Fix refcount leak and __iomem leak bugs In brcmstb_pm_probe(), there are two kinds of leak bugs: (1) we need to add of_node_put() when for_each__matching_node() breaks (2) we need to add iounmap() for each iomap in fail path
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于存在refcount泄漏和__iomem泄漏漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 0b741b8234c86065fb6954d32d427b3f7e14756f ~ 0284b4e6dec6088a41607aa3f42bf51edff01883 -
Linux Linux 4.15 -

II. Public POCs for CVE-2022-48693

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-48693

登录查看更多情报信息。

Other References for CVE-2022-48693 (6)

Same Patch Batch · Linux · 2024-05-03 · 25 CVEs total

CVE-2022-48673 9.8 CRITICAL net/smc: Fix possible access to freed memory in link clear
CVE-2022-48686 9.8 CRITICAL nvme-tcp: fix UAF when detecting digest errors
CVE-2022-48697 9.8 CRITICAL nvmet: fix a use-after-free
CVE-2022-48674 7.8 HIGH erofs: fix pcluster use-after-free on UP platforms
CVE-2022-48695 7.8 HIGH scsi: mpt3sas: Fix use-after-free warning
CVE-2022-48702 7.8 HIGH ALSA: emu10k1: Fix out of bounds access in snd_emu10k1_pcm_channel_alloc()
CVE-2022-48692 7.5 HIGH RDMA/srp: Set scmnd->result only when scmnd is not NULL
CVE-2022-48694 7.5 HIGH RDMA/irdma: Fix drain SQ hang with no completion
CVE-2022-48696 7.1 HIGH regmap: spi: Reserve space for register address/padding
CVE-2022-48705 wifi: mt76: mt7921e: fix crash in chip reset fail
CVE-2022-48670 peci: cpu: Fix use-after-free in adev_release()
CVE-2022-48704 drm/radeon: add a force flush to delay work when radeon
CVE-2022-48690 ice: Fix DMA mappings leak
CVE-2022-48703 thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR
CVE-2022-48701 ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface()
CVE-2022-48699 sched/debug: fix dentry leak in update_sched_domain_debugfs
CVE-2022-48698 drm/amd/display: fix memory leak when using debugfs_lookup()
CVE-2022-48691 netfilter: nf_tables: clean up hook list when offload flags check fails
CVE-2022-48689 tcp: TX zerocopy should not sense pfmemalloc status
CVE-2022-48688 i40e: Fix kernel crash during module removal

Showing top 20 of 25 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-48693

No comments yet


Leave a comment