Linux · Linux Kernel · CVE-2022-49626
**Name of the Vulnerable Software and Affected Versions**
Linux kernel (affected versions not specified)
**Description**
A use-after-free issue has been detected in the Linux kernel when disabling SR-IOV. The issue occurs when the `vf->pci dev` pointer is freed from `pci disable sriov` and later read in `efx ef10 sriov free vf vports`, called from `efx ef10 sriov free vf vswitching`. This can be triggered by writing to the `/sys/class/net/enp65s0f0np0/device/sriov numvfs` file. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.