PT-2022-6248 · Linux+10 · Linux Kernel+10

Hyunwoo Kim

·

Published

2022-11-15

·

Updated

2024-06-15

·

CVE-2022-45886

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.0.9
Description The issue is related to a use-after-free condition in the Linux kernel's DVB driver, specifically in the drivers/media/dvb-core/dvb net.c module. This condition is caused by a race between the disconnect and dvb device open functions. Exploitation of this issue could allow an attacker to cause a denial of service or elevate their privileges.
Recommendations For Linux kernel versions prior to 6.0.9, consider updating to a version 6.0.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable module drivers/media/dvb-core/dvb net.c to minimize the risk of exploitation. Avoid using the dvb device open function in conjunction with the disconnect function until the issue is resolved.

Exploit

Fix

Use After Free

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:7549
ALT-PU-2022-3220
ALT-PU-2022-3303
ALT-PU-2022-3364
ALT-PU-2022-3371
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
ALT-PU-2023-8461
AZL-11485
BDU:2023-00645
CESA-2023_7548
CESA-2023_7549
CVE-2022-45886
OESA-2023-1448
OPENSUSE-SU-2023_2646-1
OPENSUSE-SU-2023_2871-1
OPENSUSE-SU-2024:12994-1
OPENSUSE-SU-2024:13704-1
RHSA-2023:7398
RHSA-2023:7539
RHSA-2023:7548
RHSA-2023:7549
RHSA-2023_7548
RHSA-2023_7549
RLSA-2023:7548
RLSA-2023:7549
RXSA-2023:7549
SUSE-SU-2023:2500-1
SUSE-SU-2023:2501-1
SUSE-SU-2023:2502-1
SUSE-SU-2023:2507-1
SUSE-SU-2023:2534-1
SUSE-SU-2023:2537-1
SUSE-SU-2023:2538-1
SUSE-SU-2023:2611-1
SUSE-SU-2023:2646-1
SUSE-SU-2023:2651-1
SUSE-SU-2023:2653-1
SUSE-SU-2023:2782-1
SUSE-SU-2023:2805-1
SUSE-SU-2023:2809-1
SUSE-SU-2023:2871-1
USN-6412-1
USN-6466-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu