CVE-2022-49997

MEDIUM

Linux Kernel 5.4.128-5.5 - Use-After-Free in lantiq_xrx200 Buffer Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: lantiq_xrx200: restore buffer if memory allocation failed In a situation where memory allocation fails, an invalid buffer address is stored. When this descriptor is used again, the system panics in the build_skb() function when accessing memory.

Scores

CVSS v3 5.5
EPSS 0.0018
EPSS Percentile 7.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-401
Status published
Products (15)
Linux/Linux < 5.13
Linux/Linux 217395c5ab15e92a4fd84fe77fab6b0b1bb4e456
Linux/Linux 5.10.46 - 5.11
Linux/Linux 5.12.13 - 5.13
Linux/Linux 5.13
Linux/Linux 5.19.6 - 5.19.*
Linux/Linux 5.4.128 - 5.5
Linux/Linux 5e006cdb9b759f604c4fc69b410aab37cf45f5b4
Linux/Linux 6.0
Linux/Linux 70c8418469fb22a679fe5015ebe60fe15011ea43
... and 5 more
Published Jun 18, 2025
Tracked Since Feb 18, 2026