CVE-2022-49385
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
driver: base: fix UAF when driver_attach failed
When driver_attach(drv); failed, the driver_private will be freed. But it has been added to the bus, which caused a UAF.
To fix it, we need to delete it from the bus when failed.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 190888ac01d059e38ffe77a2291d44cafa9016fb < 5d709f58c743166fe1c6914b9de0ae8868600d9b | affected |
| Linux | Linux | 190888ac01d059e38ffe77a2291d44cafa9016fb < 823f24f2e329babd0330200d0b74882516fe57f4 | affected |
| Linux | Linux | 190888ac01d059e38ffe77a2291d44cafa9016fb < cdf1a683a01583bca4b618dd16223cbd6e462e21 | affected |
| Linux | Linux | 190888ac01d059e38ffe77a2291d44cafa9016fb < 5389101257828d1913d713d9a40acbe14f5961df | affected |
| Linux | Linux | 190888ac01d059e38ffe77a2291d44cafa9016fb < c059665c84feab46b7173d3a1bf36c2fb7f9df86 | affected |
| Linux | Linux | 190888ac01d059e38ffe77a2291d44cafa9016fb < 310862e574001a97ad02272bac0fd13f75f42a27 | affected |
| Linux | Linux | 3.9 | affected |
| Linux | Linux | 0 < 3.9 | unaffected |
| Linux | Linux | 5.4.198 <= 5.4.* | unaffected |
| Linux | Linux | 5.10.122 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.47 <= 5.15.* | unaffected |
| Linux | Linux | 5.17.15 <= 5.17.* | unaffected |
| Linux | Linux | 5.18.4 <= 5.18.* | unaffected |
| Linux | Linux | 5.19 <= * | unaffected |
Weaknesses
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://git.kernel.org/stable/c/5d709f58c743166fe1c6914b9de0ae8868600d9b
- https://git.kernel.org/stable/c/823f24f2e329babd0330200d0b74882516fe57f4
- https://git.kernel.org/stable/c/cdf1a683a01583bca4b618dd16223cbd6e462e21
- https://git.kernel.org/stable/c/5389101257828d1913d713d9a40acbe14f5961df
- https://git.kernel.org/stable/c/c059665c84feab46b7173d3a1bf36c2fb7f9df86
- https://git.kernel.org/stable/c/310862e574001a97ad02272bac0fd13f75f42a27
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.