CVE-2022-48637
Last modified
CVE-2022-48637 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: bnxt: prevent skb UAF after handing over to PTP worker When reading the timestamp is required bnxt_tx_int() hands over the ownership of the completed skb to the PTP worker. The skb should not be used afterwards, as the worker may run before the rest of our code and free the skb, leading to a use-after-free. Since dev_kfree_skb_any() accepts NULL make the loss of ownership more obvious and set skb to NULL.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: bnxt: prevent skb UAF after handing over to PTP worker When reading the timestamp is required bnxt_tx_int() hands over the ownership of the completed skb to the PTP worker. The skb should not be used afterwards, as the worker may run before the rest of our code and free the skb, leading to a use-after-free. Since dev_kfree_skb_any() accepts NULL make the loss of ownership more obvious and set skb to NULL.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 5.14, < 5.15.71 | — |
| Linux | Linux Kernel | >= 5.16, < 5.19.12 | — |
| Linux | Linux Kernel | 6.0 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-48637?
How severe is CVE-2022-48637?
How do I fix CVE-2022-48637?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-48631In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-48632In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-48633In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-48634In the Linux kernel, the following vulnerability has been re…5.3
- CVE-2022-48635In the Linux kernel, the following vulnerability has been re…6.2
- CVE-2022-48636In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-48638In the Linux kernel, the following vulnerability has been re…5.3
- CVE-2022-48639In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-4864Argument Injection in GitHub repository froxlor/froxlor prio…5.4
- CVE-2022-48640In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-48641In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-48642In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2022-48637?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
