CVE-2022-48641

MEDIUM

Linux Kernel Use-After-Free in ebtables Blob Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix memory leak when blob is malformed The bug fix was incomplete, it "replaced" crash with a memory leak. The old code had an assignment to "ret" embedded into the conditional, restore this.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (20)
linux/Kernel 4.14.292 - 4.14.295linux
linux/Kernel 4.19.257 - 4.19.260linux
linux/Kernel 5.10.140 - 5.10.146linux
linux/Kernel 5.15.64 - 5.15.71linux
linux/Kernel 5.19.6 - 5.19.12linux
linux/Kernel 5.4.212 - 5.4.215linux
Linux/Linux 160c4eb47db03b96c0c425358e7595ebefe8094d - 11ebf32fde46572b0aaf3c2bdd97d923ef5a03ab
Linux/Linux 1b2c5428f773d60c116c7b1e390432e0cfb63cd6 - d5917b7af7cae0e2804f9d127a03268035098b7f
Linux/Linux 358765beb836f5fc2ed26b5df4140d5d3548ac11 - 1e98318af2f163eadaff815abcef38d27ca92c1e
Linux/Linux 4.14.292 - 4.14.295
... and 10 more
Published Apr 28, 2024
Tracked Since Feb 18, 2026