PT-2024-9254 · Linux+7 · Linux Kernel+7

Marek Behún

·

Published

2024-06-20

·

Updated

2025-09-29

·

CVE-2022-48754

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to a potential use-after-free error in the phylib component of the Linux kernel. This error occurs because the phy device reset(phydev) function is called after the put device() call in phy detach(), which might cause the phydev to be freed prematurely. The comment before the put device() call indicates that the phydev might go away with put device(). To fix this, the phy device reset() function should be called before put device(). The vulnerability may allow an attacker to elevate privileges in the system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:7000
ALSA-2024:7001
ALSA-2025_16880
BDU:2024-10942
CESA-2024_7000
CESA-2024_7001
CVE-2022-48754
INFSA-2024_7000
INFSA-2024_7001
OPENSUSE-SU-2024_2362-1
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
RHSA-2024:6206
RHSA-2024:7000
RHSA-2024:7001
RHSA-2024_7000
RHSA-2024_7001
RLSA-2024:7001
SUSE-SU-2024:2360-1
SUSE-SU-2024:2362-1
SUSE-SU-2024:2372-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2384-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2561-1
SUSE-SU-2024:2902-1
SUSE-SU-2024:2929-1
SUSE-SU-2024:2939-1

Affected Products

Almalinux
Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse