Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: e100: Fix possible use after free in e100_xmit_prepare In e100_xmit_prepare(), if we can't map the skb, then return -ENOMEM, so e100_xmit_frame() will return NETDEV_TX_BUSY and the upper layer will resend the skb. But the skb is already freed, which will cause UAF bug when the upper layer resends the skb. Remove the harmful free.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.3, < 5.10.158 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/45605c75c52c7ae7bfe902214343aabcfe5ba0ffPatch
- https://git.kernel.org/stable/c/9fc27d22cdb9b1fcd754599d216a8992fed280cdPatch
- https://git.kernel.org/stable/c/b46f6144ab89d3d757ead940759c505091626a7dPatch
- https://git.kernel.org/stable/c/b775f37d943966f6f77dca402f5a9dedce502c25Patch
FAQ
What is CVE-2022-49026?
CVE-2022-49026 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: e100: Fix possible use after free in e100_xmit_prepare In e100_xmit_prepare(), if we can't map the skb, then return -ENOMEM, so e1...
How severe is CVE-2022-49026?
CVE-2022-49026 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-49026?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.