Review reviewHigh

CVE-2022-49015

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: net: hsr: Fix potential use-after-free The skb is delivered to netif_rx() which may free it, after calling this, dereferencing skb may trigger use-after-free.

CVSS
7.8
EPSS
0.35%
27.4% percentile
CISA KEV
Not listed
Published
2024.10.22
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.35%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net: hsr: Fix potential use-after-free The skb is delivered to netif_rx() which may free it, after calling this, dereferencing skb may trigger use-after-free.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= f421436a591d34fa5279b54a96ac07d70250cc8d < 8393ce5040803666bfa26a3a7bf41e44fab0ace9, >= f421436a591d34fa5279b54a96ac07d70250cc8d < 4b351609af4fdbc23f79ab2b12748f4403ea9af4, >= f421436a591d34fa5279b54a96ac07d70250cc8d < b35d899854d5d5d58eb7d7e7c0f61afc60d3a9e9, >= f421436a591d34fa5279b54a96ac07d70250cc8d < 53a62c5efe91665f7a41fad0f888a96f94dc59eb, >= f421436a591d34fa5279b54a96ac07d70250cc8d < 7ca81a161e406834a1fdc405fc83a572bd14b8d9, >= f421436a591d34fa5279b54a96ac07d70250cc8d < dca370e575d9b6c983f5015e8dc035e23e219ee6, >= f421436a591d34fa5279b54a96ac07d70250cc8d < f3add2b8cf620966de3ebfa07679ca12d33ec26f, >= f421436a591d34fa5279b54a96ac07d70250cc8d < 7e177d32442b7ed08a9fa61b61724abc548cb248, >= 3.13, >= 3.13 < 4.9.335, >= 4.10 < 4.14.301, >= 4.15 < 4.19.268, >= 4.20 < 5.4.226, >= 5.5 < 5.10.158, >= 5.11 < 5.15.82, >= 5.16 < 6.0.12, 6.1
Fixed versions
4.9.335, 4.14.301, 4.19.268, 5.4.226, 5.10.158, 5.15.82, 6.0.12

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2022-49015 — Linux Linux, linux kernel | SECUFOCUS NOW