CVE-2022-48779

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
16/07/2024
Last modified:
21/08/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: mscc: ocelot: fix use-after-free in ocelot_vlan_del()<br /> <br /> ocelot_vlan_member_del() will free the struct ocelot_bridge_vlan, so if<br /> this is the same as the port&amp;#39;s pvid_vlan which we access afterwards,<br /> what we&amp;#39;re accessing is freed memory.<br /> <br /> Fix the bug by determining whether to clear ocelot_port-&gt;pvid_vlan prior<br /> to calling ocelot_vlan_member_del().

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 5.16.11 (excluding)