目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2022-48703— Linux kernel 安全漏洞

AI Predicted 5.5 Difficulty: Easy EPSS 0.23% · P14

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 10

ベンダープロダクトVersion Rangeステータス
LinuxLinux0ba13c763aacb27ab32bde5d559bf40e88465921< 722588f17fd3d3a127e50718ec2caf22bd7e9daaaffected
0ba13c763aacb27ab32bde5d559bf40e88465921< 39d5137085a6c37ace4680ee4d24020a4a03e7dcaffected
0ba13c763aacb27ab32bde5d559bf40e88465921< dae42083b045a4ddf71c57cf350cb2412b5915c2affected
0ba13c763aacb27ab32bde5d559bf40e88465921< 7931e28098a4c1a2a6802510b0cbe57546d2049daffected
5.8affected
< 5.8unaffected
5.10.258≤ 5.10.*unaffected
5.15.189≤ 5.15.*unaffected
… +2 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2022-48703の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR In some case, the GDDV returns a package with a buffer which has zero length. It causes that kmemdup() returns ZERO_SIZE_PTR (0x10). Then the data_vault_read() got NULL point dereference problem when accessing the 0x10 value in data_vault. [ 71.024560] BUG: kernel NULL pointer dereference, address: 0000000000000010 This patch uses ZERO_OR_NULL_PTR() for checking ZERO_SIZE_PTR or NULL value in data_vault.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于存在空指针取消引用漏洞。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 0ba13c763aacb27ab32bde5d559bf40e88465921 ~ 722588f17fd3d3a127e50718ec2caf22bd7e9daa -
LinuxLinux 5.8 -

II. CVE-2022-48703の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2022-48703のインテリジェンス情報

登录查看更多情报信息。

CVE-2022-48703 补丁与修复 (1)

CVE-2022-48703 其他参考 (2)

Same Patch Batch · Linux · 2024-05-03 · 25 CVEs total

CVE-2022-486739.8 CRITICALnet/smc: Fix possible access to freed memory in link clear
CVE-2022-486869.8 CRITICALnvme-tcp: fix UAF when detecting digest errors
CVE-2022-486979.8 CRITICALnvmet: fix a use-after-free
CVE-2022-486747.8 HIGHerofs: fix pcluster use-after-free on UP platforms
CVE-2022-486957.8 HIGHscsi: mpt3sas: Fix use-after-free warning
CVE-2022-487027.8 HIGHALSA: emu10k1: Fix out of bounds access in snd_emu10k1_pcm_channel_alloc()
CVE-2022-486927.5 HIGHRDMA/srp: Set scmnd->result only when scmnd is not NULL
CVE-2022-486947.5 HIGHRDMA/irdma: Fix drain SQ hang with no completion
CVE-2022-486967.1 HIGHregmap: spi: Reserve space for register address/padding
CVE-2022-48693soc: brcmstb: pm-arm: Fix refcount leak and __iomem leak bugs
CVE-2022-48705wifi: mt76: mt7921e: fix crash in chip reset fail
CVE-2022-48704drm/radeon: add a force flush to delay work when radeon
CVE-2022-48690ice: Fix DMA mappings leak
CVE-2022-48701ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface()
CVE-2022-48699sched/debug: fix dentry leak in update_sched_domain_debugfs
CVE-2022-48698drm/amd/display: fix memory leak when using debugfs_lookup()
CVE-2022-48670peci: cpu: Fix use-after-free in adev_release()
CVE-2022-48691netfilter: nf_tables: clean up hook list when offload flags check fails
CVE-2022-48689tcp: TX zerocopy should not sense pfmemalloc status
CVE-2022-48688i40e: Fix kernel crash during module removal

Showing 20 of 25 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2022-48703へのコメント

まだコメントはありません


コメントを残す