Review reviewHigh

CVE-2022-48872

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix use-after-free race condition for maps It is possible that in between calling fastrpc_map_get() until map->fl->lock is taken in fastrpc_free_map(), another thread can call fastrpc_map_lookup() and get a reference to a map that is about to be deleted. Rewrite fastrpc_map_get() to only increase the reference count of a map if it's non-zero. Propagate this to callers so they can know if a map is about to be deleted. Fixes this warning: refcount_t: addition on 0; use-after-free. WARNING: CPU: 5 PID: 10100 at...

CVSS
7
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.08.21
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix use-after-free race condition for maps It is possible that in between calling fastrpc_map_get() until map->fl->lock is taken in fastrpc_free_map(), another thread can call fastrpc_map_lookup() and get a reference to a map that is about to be deleted. Rewrite fastrpc_map_get() to only increase the reference count of a map if it's non-zero. Propagate this to callers so they can know if a map is about to be deleted. Fixes this warning: refcount_t: addition on 0; use-after-free. WARNING: CPU: 5 PID: 10100 at...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= c68cfb718c8f97b7f7a50ed66be5feb42d0c8988 < 556dfdb226ce1e5231d8836159b23f8bb0395bf4, >= c68cfb718c8f97b7f7a50ed66be5feb42d0c8988 < b171d0d2cf1b8387c72c8d325c5d5746fa271e39, >= c68cfb718c8f97b7f7a50ed66be5feb42d0c8988 < 61a0890cb95afec5c8a2f4a879de2b6220984ef1, >= c68cfb718c8f97b7f7a50ed66be5feb42d0c8988 < 079c78c68714f7d8d58e66c477b0243b31806907, >= c68cfb718c8f97b7f7a50ed66be5feb42d0c8988 < 96b328d119eca7563c1edcc4e1039a62e6370ecb, >= 5.1, >= 5.1 < 5.4.230, >= 5.5 < 5.10.165, >= 5.11 < 5.15.90, >= 5.16 < 6.2, 6.2
Fixed versions
5.4.230, 5.10.165, 5.15.90, 6.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416