PT-2022-7428 · Linux+2 · Linux Kernel+2

Alexey Khoroshilov

·

Published

2022-02-16

·

Updated

2024-08-22

·

CVE-2022-48783

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a use-after-free vulnerability in the gswip remove() function of the Lantiq / Intel GSWIP driver in the Linux kernel. This vulnerability is associated with the reuse of previously freed memory. Exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is located in the drivers/net/dsa/lantiq gswip.c module. Technical details about exploitation include the incorrect order of operations, specifically that of node put(priv->ds->slave mii bus->dev.of node) should be done before mdiobus free(priv->ds->slave mii bus).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06076
CVE-2022-48783
OPENSUSE-SU-2024_2947-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2902-1
SUSE-SU-2024:2929-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2947-1

Affected Products

Linux Kernel
Red Os
Suse