CVE-2022-49997
MEDIUMLinux Kernel 5.4.128-5.5 - Use-After-Free in lantiq_xrx200 Buffer Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: net: lantiq_xrx200: restore buffer if memory allocation failed In a situation where memory allocation fails, an invalid buffer address is stored. When this descriptor is used again, the system panics in the build_skb() function when accessing memory.
References (2)
Core 2
Scores
CVSS v3
5.5
EPSS
0.0018
EPSS Percentile
7.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-401
Status
published
Products (15)
Linux/Linux
< 5.13
Linux/Linux
217395c5ab15e92a4fd84fe77fab6b0b1bb4e456
Linux/Linux
5.10.46 - 5.11
Linux/Linux
5.12.13 - 5.13
Linux/Linux
5.13
Linux/Linux
5.19.6 - 5.19.*
Linux/Linux
5.4.128 - 5.5
Linux/Linux
5e006cdb9b759f604c4fc69b410aab37cf45f5b4
Linux/Linux
6.0
Linux/Linux
70c8418469fb22a679fe5015ebe60fe15011ea43
... and 5 more
Published
Jun 18, 2025
Tracked Since
Feb 18, 2026