Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-48924— thermal: int340x: fix memory leak in int3400_notify()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在int3400_notify函数中存在内存泄漏问题。

AI Predicted 5.5 Difficulty: Theoretical EPSS 0.21% · P11

Possible ATT&CK Techniques 1 AI

T1562.008

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux 38e44da591303d08b0d965a033e11ade284999d0< f0ddc5184b0127038d05008e2a69f89d1e13f980 affected
38e44da591303d08b0d965a033e11ade284999d0< c3fa6d1937a8d0828131a04ae2cd2c30d0668693 affected
38e44da591303d08b0d965a033e11ade284999d0< 2e798814e01827871938ff172d2b2ccf1e74b355 affected
38e44da591303d08b0d965a033e11ade284999d0< e098933866f9e1dd3ef4eebbe2e3d504f970f599 affected
38e44da591303d08b0d965a033e11ade284999d0< ba9efbbf6745750d34c1e87c9539ce9db645ca0a affected
38e44da591303d08b0d965a033e11ade284999d0< 33c73a4d7e7b19313a6b417152f5365016926418 affected
38e44da591303d08b0d965a033e11ade284999d0< 3abea10e6a8f0e7804ed4c124bea2d15aca977c8 affected
4.14 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-48924

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
thermal: int340x: fix memory leak in int3400_notify()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: fix memory leak in int3400_notify() It is easy to hit the below memory leaks in my TigerLake platform: unreferenced object 0xffff927c8b91dbc0 (size 32): comm "kworker/0:2", pid 112, jiffies 4294893323 (age 83.604s) hex dump (first 32 bytes): 4e 41 4d 45 3d 49 4e 54 33 34 30 30 20 54 68 65 NAME=INT3400 The 72 6d 61 6c 00 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b a5 rmal.kkkkkkkkkk. backtrace: [<ffffffff9c502c3e>] __kmalloc_track_caller+0x2fe/0x4a0 [<ffffffff9c7b7c15>] kvasprintf+0x65/0xd0 [<ffffffff9c7b7d6e>] kasprintf+0x4e/0x70 [<ffffffffc04cb662>] int3400_notify+0x82/0x120 [int3400_thermal] [<ffffffff9c8b7358>] acpi_ev_notify_dispatch+0x54/0x71 [<ffffffff9c88f1a7>] acpi_os_execute_deferred+0x17/0x30 [<ffffffff9c2c2c0a>] process_one_work+0x21a/0x3f0 [<ffffffff9c2c2e2a>] worker_thread+0x4a/0x3b0 [<ffffffff9c2cb4dd>] kthread+0xfd/0x130 [<ffffffff9c201c1f>] ret_from_fork+0x1f/0x30 Fix it by calling kfree() accordingly.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在int3400_notify函数中存在内存泄漏问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 38e44da591303d08b0d965a033e11ade284999d0 ~ f0ddc5184b0127038d05008e2a69f89d1e13f980 -
Linux Linux 4.14 -

II. Public POCs for CVE-2022-48924

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-48924

登录查看更多情报信息。

Other References for CVE-2022-48924 (7)

Same Patch Batch · Linux · 2024-08-22 · 42 CVEs total

CVE-2022-48941 8.8 HIGH ice: fix concurrent reset and removal of VFs
CVE-2022-48919 8.8 HIGH cifs: fix double free race when mount fails in cifs_get_root()
CVE-2022-48925 7.8 HIGH RDMA/cma: Do not change route.addr.src_addr outside state checks
CVE-2022-48923 7.8 HIGH btrfs: prevent copying too big compressed lzo segment
CVE-2022-48927 7.8 HIGH iio: adc: tsc2046: fix memory corruption by preventing array overflow
CVE-2022-48913 7.8 HIGH blktrace: fix use after free for struct blk_trace
CVE-2022-48912 7.8 HIGH netfilter: fix use-after-free in __nf_register_net_hook()
CVE-2022-48911 7.8 HIGH netfilter: nf_queue: fix possible use-after-free
CVE-2022-48932 7.8 HIGH net/mlx5: DR, Fix slab-out-of-bounds in mlx5_cmd_dr_create_fte
CVE-2022-48935 7.8 HIGH netfilter: nf_tables: unregister flowtable hooks on netns exit
CVE-2022-48940 7.8 HIGH bpf: Fix crash due to incorrect copy_map_value
CVE-2022-48943 7.1 HIGH KVM: x86/mmu: make apf token non-zero to fix bug
CVE-2022-48933 netfilter: nf_tables: fix memory leak during stateful obj update
CVE-2022-48931 configfs: fix a race in configfs_{,un}register_subsystem()
CVE-2022-48934 nfp: flower: Fix a potential leak in nfp_tunnel_add_shared_mac()
CVE-2022-48937 io_uring: add a schedule point in io_add_buffers()
CVE-2022-48930 RDMA/ib_srp: Fix a deadlock
CVE-2022-48929 bpf: Fix crash due to out of bounds access into reg2btf_ids.
CVE-2022-48928 iio: adc: men_z188_adc: Fix a resource leak in an error handling path
CVE-2022-48938 CDC-NCM: avoid overflow in sanity checking

Showing top 20 of 42 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-48924

No comments yet


Leave a comment