PT-2022-7482 · Linux+7 · Linux Kernel+7
Shyam Prasad N
·
Published
2022-02-13
·
Updated
2025-09-29
·
CVE-2022-48919
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.17.0-rc3+
Description
The vulnerability is related to a double free race condition in the cifs component of the Linux kernel. When cifs get root() fails during cifs smb3 do mount(), the kernel calls deactivate locked super(), which eventually calls delayed free() to free the context. However, in this situation, the kernel should not proceed to enter the out section in cifs smb3 do mount() and free the same resources a second time. This vulnerability can be exploited to impact the confidentiality, integrity, and availability of protected information.
Recommendations
To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, versions 5.17.0-rc3 and later should be used.
Note: The provided information does not specify the exact version where the fix is included, but it is mentioned that the issue is resolved in version 5.17.0-rc3+. Therefore, updating to this version or later should mitigate the vulnerability.
If updating is not possible, consider implementing additional security measures to minimize the risk of exploitation, such as restricting access to the cifs component or monitoring for suspicious activity. However, these measures are not a replacement for updating the kernel to a patched version.
At the moment, there is no information about other versions that contain a fix for this vulnerability.
Exploit
Fix
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse