Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于mctp模块中发现内存使用后释放问题。mctp_key_add函数失败时释放了key,但后续仍在trace_mctp_key_acquire函数中使用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 4f9e1ba6de45aa8797a83f1fe5b82ec4bac16899< 1dd3ecbec5f606b2a526c47925c8634b1a6bb81e |
affected |
4f9e1ba6de45aa8797a83f1fe5b82ec4bac16899< 7e5b6a5c8c44310784c88c1c198dde79f6402f7b |
affected | ||
5.16 |
affected | ||
< 5.16 |
unaffected | ||
5.16.11≤ 5.16.* |
unaffected | ||
5.17≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-48790 | 9.8 CRITICAL | nvme: fix a possible use-after-free in controller reset during load |
| CVE-2022-48789 | 9.8 CRITICAL | nvme-tcp: fix possible use-after-free in transport error_recovery work |
| CVE-2022-48788 | 9.8 CRITICAL | nvme-rdma: fix possible use-after-free in transport error_recovery work |
| CVE-2022-48851 | 9.8 CRITICAL | staging: gdm724x: fix use after free in gdm_lte_rx() |
| CVE-2022-48829 | 9.1 CRITICAL | NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes |
| CVE-2022-48828 | 9.1 CRITICAL | NFSD: Fix ia_size underflow |
| CVE-2022-48864 | 8.8 HIGH | vdpa/mlx5: add validation for VIRTIO_NET_CTRL_MQ_VQ_PAIRS_SET command |
| CVE-2022-48830 | 8.8 HIGH | can: isotp: fix potential CAN frame reception race in isotp_rcv() |
| CVE-2022-48785 | 8.8 HIGH | ipv6: mcast: use rcu-safe version of ipv6_get_lladdr() |
| CVE-2022-48786 | 7.8 HIGH | vsock: remove vsock from connected table when connect is interrupted by a signal |
| CVE-2022-48847 | 7.8 HIGH | watch_queue: Fix filter limit check |
| CVE-2022-48779 | 7.8 HIGH | net: mscc: ocelot: fix use-after-free in ocelot_vlan_del() |
| CVE-2022-48821 | 7.8 HIGH | misc: fastrpc: avoid double fput() on failed usercopy |
| CVE-2022-48822 | 7.8 HIGH | usb: f_fs: Fix use-after-free for epfile |
| CVE-2022-48839 | 7.8 HIGH | net/packet: fix slab-out-of-bounds access in packet_recvmsg() |
| CVE-2022-48801 | 7.8 HIGH | iio: buffer: Fix file related error handling in IIO_BUFFER_GET_FD_IOCTL |
| CVE-2022-48792 | 7.8 HIGH | scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task |
| CVE-2022-48796 | 7.8 HIGH | iommu: Fix potential use-after-free during probe |
| CVE-2022-48787 | 7.8 HIGH | iwlwifi: fix use-after-free |
| CVE-2022-48791 | 7.8 HIGH | scsi: pm8001: Fix use-after-free for aborted TMF sas_task |
Showing top 20 of 98 CVEs. View all on vendor page → →
No comments yet