PT-2022-7482 · Linux+7 · Linux Kernel+7

Shyam Prasad N

·

Published

2022-02-13

·

Updated

2025-09-29

·

CVE-2022-48919

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17.0-rc3+
Description The vulnerability is related to a double free race condition in the cifs component of the Linux kernel. When cifs get root() fails during cifs smb3 do mount(), the kernel calls deactivate locked super(), which eventually calls delayed free() to free the context. However, in this situation, the kernel should not proceed to enter the out section in cifs smb3 do mount() and free the same resources a second time. This vulnerability can be exploited to impact the confidentiality, integrity, and availability of protected information.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, versions 5.17.0-rc3 and later should be used.
Note: The provided information does not specify the exact version where the fix is included, but it is mentioned that the issue is resolved in version 5.17.0-rc3+. Therefore, updating to this version or later should mitigate the vulnerability.
If updating is not possible, consider implementing additional security measures to minimize the risk of exploitation, such as restricting access to the cifs component or monitoring for suspicious activity. However, these measures are not a replacement for updating the kernel to a patched version.
At the moment, there is no information about other versions that contain a fix for this vulnerability.

Exploit

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:9580
ALSA-2025:9581
ALSA-2025_16880
ALSA-2025_9580
ALSA-2025_9581
BDU:2024-06628
CESA-2025_9580
CESA-2025_9581
CVE-2022-48919
INFSA-2025_9580
INFSA-2025_9581
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3249-1
OPENSUSE-SU-2024_3408-1
OPENSUSE-SU-2024_3483-1
RHSA-2025:9580
RHSA-2025:9581
RHSA-2025_9580
RHSA-2025_9581
SUSE-SU-2024:3189-1
SUSE-SU-2024:3190-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3225-1
SUSE-SU-2024:3227-1
SUSE-SU-2024:3249-1
SUSE-SU-2024:3251-1
SUSE-SU-2024:3252-1
SUSE-SU-2024:3408-1
SUSE-SU-2024:3467-1
SUSE-SU-2024:3483-1
SUSE-SU-2024:3499-1

Affected Products

Almalinux
Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse