Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: driver: base: fix UAF when driver_attach failed When driver_attach(drv); failed, the driver_private will be freed. But it has been added to the bus, which caused a UAF. To fix it, we need to delete it from the bus when failed.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.9, < 5.4.198 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/310862e574001a97ad02272bac0fd13f75f42a27Patch
- https://git.kernel.org/stable/c/5389101257828d1913d713d9a40acbe14f5961dfPatch
- https://git.kernel.org/stable/c/5d709f58c743166fe1c6914b9de0ae8868600d9bPatch
- https://git.kernel.org/stable/c/823f24f2e329babd0330200d0b74882516fe57f4Patch
- https://git.kernel.org/stable/c/c059665c84feab46b7173d3a1bf36c2fb7f9df86Patch
- https://git.kernel.org/stable/c/cdf1a683a01583bca4b618dd16223cbd6e462e21Patch
FAQ
What is CVE-2022-49385?
CVE-2022-49385 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: driver: base: fix UAF when driver_attach failed When driver_attach(drv); failed, the driver_private will be freed. But it has been...
How severe is CVE-2022-49385?
CVE-2022-49385 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-49385?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.