目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2022-48787— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.24% · P15

Affected Version Matrix 13

ベンダープロダクトVersion Rangeステータス
LinuxLinux8e10749fa1a454c1e7214f36cec83241f5a36ef1< d3b98fe36f8a06ce654049540773256ab59cb53daffected
1d7cc54137a4f28506dc7beac235b240b08f4e59< 7d6475179b85a83186ccce59cdc359d4f07d0bcbaffected
0446cafa843e6db4982731c167e11c80d42be7e2< 494de920d98f125b099f27a2d274850750aff957affected
febab6b60d61d13cd9f30a2991deea56df39567d< 008508c16af0087cda0394e1ac6f0493b01b6063affected
e23f075d77987de4215c8e0696f28bcc707506f7< ddd46059f7d99119b62d44c519df7a79f2e6a515affected
6b5ad4bd0d78fef6bbe0ecdf96e09237c9c52cc1< 9958b9cbb22145295ee1ffaea0904c383da2c05daffected
ab07506b0454bea606095951e19e72c282bfbb42< bea2662e7818e15d7607d17d57912ac984275d94affected
4.14.263< 4.14.268affected
… +5 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2022-48787の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
iwlwifi: fix use-after-free
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: iwlwifi: fix use-after-free If no firmware was present at all (or, presumably, all of the firmware files failed to parse), we end up unbinding by calling device_release_driver(), which calls remove(), which then in iwlwifi calls iwl_drv_stop(), freeing the 'drv' struct. However the new code I added will still erroneously access it after it was freed. Set 'failure=false' in this case to avoid the access, all data was already freed anyway.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于iwlwifi模块中发现释放后重用问题。如果没有固件或固件文件解析失败,调用device_release_driver函数时会错误地访问已释放的drv结构体。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 8e10749fa1a454c1e7214f36cec83241f5a36ef1 ~ d3b98fe36f8a06ce654049540773256ab59cb53d -
LinuxLinux 4.14.263 ~ 4.14.268 -

II. CVE-2022-48787の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2022-48787のインテリジェンス情報

登录查看更多情报信息。

CVE-2022-48787 其他参考 (6)

Same Patch Batch · Linux · 2024-07-16 · 98 CVEs total

CVE-2022-487909.8 CRITICALnvme: fix a possible use-after-free in controller reset during load
CVE-2022-488519.8 CRITICALstaging: gdm724x: fix use after free in gdm_lte_rx()
CVE-2022-487889.8 CRITICALnvme-rdma: fix possible use-after-free in transport error_recovery work
CVE-2022-487899.8 CRITICALnvme-tcp: fix possible use-after-free in transport error_recovery work
CVE-2022-488289.1 CRITICALNFSD: Fix ia_size underflow
CVE-2022-488299.1 CRITICALNFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes
CVE-2022-488648.8 HIGHvdpa/mlx5: add validation for VIRTIO_NET_CTRL_MQ_VQ_PAIRS_SET command
CVE-2022-488308.8 HIGHcan: isotp: fix potential CAN frame reception race in isotp_rcv()
CVE-2022-487828.8 HIGHmctp: fix use after free
CVE-2022-487858.8 HIGHipv6: mcast: use rcu-safe version of ipv6_get_lladdr()
CVE-2022-487867.8 HIGHvsock: remove vsock from connected table when connect is interrupted by a signal
CVE-2022-487927.8 HIGHscsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task
CVE-2022-487917.8 HIGHscsi: pm8001: Fix use-after-free for aborted TMF sas_task
CVE-2022-488167.8 HIGHSUNRPC: lock against ->sock changing during sysfs read
CVE-2022-487967.8 HIGHiommu: Fix potential use-after-free during probe
CVE-2022-488397.8 HIGHnet/packet: fix slab-out-of-bounds access in packet_recvmsg()
CVE-2022-488227.8 HIGHusb: f_fs: Fix use-after-free for epfile
CVE-2022-488217.8 HIGHmisc: fastrpc: avoid double fput() on failed usercopy
CVE-2022-488017.8 HIGHiio: buffer: Fix file related error handling in IIO_BUFFER_GET_FD_IOCTL
CVE-2024-410087.8 HIGHdrm/amdgpu: change vm->task_info handling

Showing 20 of 98 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2022-48787へのコメント

まだコメントはありません


コメントを残す