目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2022-48933— Linux kernel 安全漏洞

AI Predicted 5.5 Difficulty: Moderate EPSS 0.21% · P11

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 12

ベンダープロダクトVersion Rangeステータス
LinuxLinuxd62d0ba97b5803183e70cfded7f7b9da76893bf5< 53026346a94c43f35c32b18804041bc483271d87affected
d62d0ba97b5803183e70cfded7f7b9da76893bf5< 7e9880e81d3fd6a43c202f205717485290432826affected
d62d0ba97b5803183e70cfded7f7b9da76893bf5< e96e204ee6fa46702f6c94c3c69a09e69e0eac52affected
d62d0ba97b5803183e70cfded7f7b9da76893bf5< 34bb90e407e3288f610558beaae54ecaa32b11c4affected
d62d0ba97b5803183e70cfded7f7b9da76893bf5< dad3bdeef45f81a6e90204bcc85360bb76eccec7affected
5.4affected
< 5.4unaffected
5.4.182≤ 5.4.*unaffected
… +4 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2022-48933の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
netfilter: nf_tables: fix memory leak during stateful obj update
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memory leak during stateful obj update stateful objects can be updated from the control plane. The transaction logic allocates a temporary object for this purpose. The ->init function was called for this object, so plain kfree() leaks resources. We must call ->destroy function of the object. nft_obj_destroy does this, but it also decrements the module refcount, but the update path doesn't increment it. To avoid special-casing the update object release, do module_get for the update case too and release it via nft_obj_destroy().
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞。攻击者利用该漏洞导致内存泄漏。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux d62d0ba97b5803183e70cfded7f7b9da76893bf5 ~ 53026346a94c43f35c32b18804041bc483271d87 -
LinuxLinux 5.4 -

II. CVE-2022-48933の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2022-48933のインテリジェンス情報

登录查看更多情报信息。

CVE-2022-48933 其他参考 (5)

Same Patch Batch · Linux · 2024-08-22 · 42 CVEs total

CVE-2022-489418.8 HIGHice: fix concurrent reset and removal of VFs
CVE-2022-489198.8 HIGHcifs: fix double free race when mount fails in cifs_get_root()
CVE-2022-489237.8 HIGHbtrfs: prevent copying too big compressed lzo segment
CVE-2022-489257.8 HIGHRDMA/cma: Do not change route.addr.src_addr outside state checks
CVE-2022-489277.8 HIGHiio: adc: tsc2046: fix memory corruption by preventing array overflow
CVE-2022-489137.8 HIGHblktrace: fix use after free for struct blk_trace
CVE-2022-489127.8 HIGHnetfilter: fix use-after-free in __nf_register_net_hook()
CVE-2022-489117.8 HIGHnetfilter: nf_queue: fix possible use-after-free
CVE-2022-489327.8 HIGHnet/mlx5: DR, Fix slab-out-of-bounds in mlx5_cmd_dr_create_fte
CVE-2022-489357.8 HIGHnetfilter: nf_tables: unregister flowtable hooks on netns exit
CVE-2022-489407.8 HIGHbpf: Fix crash due to incorrect copy_map_value
CVE-2022-489437.1 HIGHKVM: x86/mmu: make apf token non-zero to fix bug
CVE-2022-48931configfs: fix a race in configfs_{,un}register_subsystem()
CVE-2022-48930RDMA/ib_srp: Fix a deadlock
CVE-2022-48934nfp: flower: Fix a potential leak in nfp_tunnel_add_shared_mac()
CVE-2022-48937io_uring: add a schedule point in io_add_buffers()
CVE-2022-48929bpf: Fix crash due to out of bounds access into reg2btf_ids.
CVE-2022-48928iio: adc: men_z188_adc: Fix a resource leak in an error handling path
CVE-2022-48938CDC-NCM: avoid overflow in sanity checking
CVE-2022-48926usb: gadget: rndis: add spinlock for rndis response list

Showing 20 of 42 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2022-48933へのコメント

まだコメントはありません


コメントを残す