CVE-2022-49385
In the Linux kernel, the following vulnerability has been resolved: driver: base: fix UAF when driver_attach failed When driver_attach(drv); failed, the driver_private will be freed.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: driver: base: fix UAF when driver_attach failed When driver_attach(drv); failed, the driver_private will be freed. But it has been added to the bus, which caused a UAF. To fix it, we need to delete it from the bus when failed.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.30% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/310862e574001a97ad02272bac0fd13f75f42a27Patch
- https://git.kernel.org/stable/c/5389101257828d1913d713d9a40acbe14f5961dfPatch
- https://git.kernel.org/stable/c/5d709f58c743166fe1c6914b9de0ae8868600d9bPatch
- https://git.kernel.org/stable/c/823f24f2e329babd0330200d0b74882516fe57f4Patch
- https://git.kernel.org/stable/c/c059665c84feab46b7173d3a1bf36c2fb7f9df86Patch
- https://git.kernel.org/stable/c/cdf1a683a01583bca4b618dd16223cbd6e462e21Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.