CVE-2022-48754
Linux Linux, linux_kernel, linux kernel
In the Linux kernel, the following vulnerability has been resolved: phylib: fix potential use-after-free Commit bafbdd527d56 ("phylib: Add device reset GPIO support") added call to phy_device_reset(phydev) after the put_device() call in phy_detach(). The comment before the put_device() call says that the phydev might go away with put_device(). Fix potential use-after-free by calling phy_device_reset() before put_device().
- CVSS
- 7.8
- EPSS
- 0.23% 13.4% percentile
- CISA KEV
- Not listed
- Published
- 2024.06.20