CVE-2022-48637 (GCVE-0-2022-48637)
Vulnerability from cvelistv5
Published
2024-04-28 12:59
Modified
2026-08-05 08:51
Summary
In the Linux kernel, the following vulnerability has been resolved: bnxt: prevent skb UAF after handing over to PTP worker When reading the timestamp is required bnxt_tx_int() hands over the ownership of the completed skb to the PTP worker. The skb should not be used afterwards, as the worker may run before the rest of our code and free the skb, leading to a use-after-free. Since dev_kfree_skb_any() accepts NULL make the loss of ownership more obvious and set skb to NULL.
Impacted products
Vendor Product Version
Linux Linux Version: 83bb623c968e7351aee5111547693f95f330dc5a
Version: 83bb623c968e7351aee5111547693f95f330dc5a
Version: 83bb623c968e7351aee5111547693f95f330dc5a
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-48637",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-06-07T17:06:57.891405Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-416",
                "description": "CWE-416 Use After Free",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-07T17:07:15.083Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T15:17:55.303Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/08483e4c0c83b221b8891434a04cec405dee94a6"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/32afa1f23e42cc635ccf4c39f24514d03d1e8338"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/c31f26c8f69f776759cbbdfb38e40ea91aa0dd65"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "08483e4c0c83b221b8891434a04cec405dee94a6",
              "status": "affected",
              "version": "83bb623c968e7351aee5111547693f95f330dc5a",
              "versionType": "git"
            },
            {
              "lessThan": "32afa1f23e42cc635ccf4c39f24514d03d1e8338",
              "status": "affected",
              "version": "83bb623c968e7351aee5111547693f95f330dc5a",
              "versionType": "git"
            },
            {
              "lessThan": "c31f26c8f69f776759cbbdfb38e40ea91aa0dd65",
              "status": "affected",
              "version": "83bb623c968e7351aee5111547693f95f330dc5a",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.14"
            },
            {
              "lessThan": "5.14",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.71",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.19.*",
              "status": "unaffected",
              "version": "5.19.12",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.71",
                  "versionStartIncluding": "5.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.19.12",
                  "versionStartIncluding": "5.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.0",
                  "versionStartIncluding": "5.14",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt: prevent skb UAF after handing over to PTP worker\n\nWhen reading the timestamp is required bnxt_tx_int() hands\nover the ownership of the completed skb to the PTP worker.\nThe skb should not be used afterwards, as the worker may\nrun before the rest of our code and free the skb, leading\nto a use-after-free.\n\nSince dev_kfree_skb_any() accepts NULL make the loss of\nownership more obvious and set skb to NULL."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The bug is in the bnxt TX completion/NAPI path and is only reached when a local process transmits PTP packets with hardware TX timestamping; a remote peer cannot trigger this via received packets alone.\nAC:L - An attacker who can send timestamped PTP frames repeatedly triggers the handoff to the PTP worker; per UAF guidance and the rule to prefer higher severity when uncertain, this is Low complexity rather than depending on uncontrolled conditions.\nPR:L - With device TX hwtstamp already enabled (typical under ptp4l), an unprivileged user can set SO_TIMESTAMPING_TX_HARDWARE and send UDP PTP event packets (port 319) with no further capabilities.\nUI:N - Exploitation requires no victim action beyond the attacker sending the crafted/timestamp-requested packets on the local system.\nS:U - Impact is confined to the same kernel privilege domain as the vulnerable driver; this is standard in-kernel memory corruption, not a cross-boundary escape.\nC:H - This is a use-after-free on an skb after the PTP worker may free it, which per kernel CVSS guidance enables high confidentiality impact via control of the freed object.\nI:H - The same skb UAF is treatable as a heap corruption primitive enabling arbitrary write/control-flow impact under standard UAF exploitation assumptions.\nA:H - Use-after-free of the skb can cause kernel oops/panic or otherwise deny service when the dangling pointer is accessed after free."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T08:51:36.351Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/08483e4c0c83b221b8891434a04cec405dee94a6"
        },
        {
          "url": "https://git.kernel.org/stable/c/32afa1f23e42cc635ccf4c39f24514d03d1e8338"
        },
        {
          "url": "https://git.kernel.org/stable/c/c31f26c8f69f776759cbbdfb38e40ea91aa0dd65"
        }
      ],
      "title": "bnxt: prevent skb UAF after handing over to PTP worker",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2022-48637",
    "datePublished": "2024-04-28T12:59:33.285Z",
    "dateReserved": "2024-02-25T13:44:28.315Z",
    "dateUpdated": "2026-08-05T08:51:36.351Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/08483e4c0c83b221b8891434a04cec405dee94a6\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/32afa1f23e42cc635ccf4c39f24514d03d1e8338\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/c31f26c8f69f776759cbbdfb38e40ea91aa0dd65\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-03T15:17:55.303Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2022-48637\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-06-07T17:06:57.891405Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-416\", \"description\": \"CWE-416 Use After Free\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-06-07T17:07:10.940Z\"}}], \"cna\": {\"title\": \"bnxt: prevent skb UAF after handing over to PTP worker\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The bug is in the bnxt TX completion/NAPI path and is only reached when a local process transmits PTP packets with hardware TX timestamping; a remote peer cannot trigger this via received packets alone.\\nAC:L - An attacker who can send timestamped PTP frames repeatedly triggers the handoff to the PTP worker; per UAF guidance and the rule to prefer higher severity when uncertain, this is Low complexity rather than depending on uncontrolled conditions.\\nPR:L - With device TX hwtstamp already enabled (typical under ptp4l), an unprivileged user can set SO_TIMESTAMPING_TX_HARDWARE and send UDP PTP event packets (port 319) with no further capabilities.\\nUI:N - Exploitation requires no victim action beyond the attacker sending the crafted/timestamp-requested packets on the local system.\\nS:U - Impact is confined to the same kernel privilege domain as the vulnerable driver; this is standard in-kernel memory corruption, not a cross-boundary escape.\\nC:H - This is a use-after-free on an skb after the PTP worker may free it, which per kernel CVSS guidance enables high confidentiality impact via control of the freed object.\\nI:H - The same skb UAF is treatable as a heap corruption primitive enabling arbitrary write/control-flow impact under standard UAF exploitation assumptions.\\nA:H - Use-after-free of the skb can cause kernel oops/panic or otherwise deny service when the dangling pointer is accessed after free.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"83bb623c968e7351aee5111547693f95f330dc5a\", \"lessThan\": \"08483e4c0c83b221b8891434a04cec405dee94a6\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"83bb623c968e7351aee5111547693f95f330dc5a\", \"lessThan\": \"32afa1f23e42cc635ccf4c39f24514d03d1e8338\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"83bb623c968e7351aee5111547693f95f330dc5a\", \"lessThan\": \"c31f26c8f69f776759cbbdfb38e40ea91aa0dd65\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/net/ethernet/broadcom/bnxt/bnxt.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.14\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.14\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.15.71\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"5.19.12\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.19.*\"}, {\"status\": \"unaffected\", \"version\": \"6.0\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/net/ethernet/broadcom/bnxt/bnxt.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/08483e4c0c83b221b8891434a04cec405dee94a6\"}, {\"url\": \"https://git.kernel.org/stable/c/32afa1f23e42cc635ccf4c39f24514d03d1e8338\"}, {\"url\": \"https://git.kernel.org/stable/c/c31f26c8f69f776759cbbdfb38e40ea91aa0dd65\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nbnxt: prevent skb UAF after handing over to PTP worker\\n\\nWhen reading the timestamp is required bnxt_tx_int() hands\\nover the ownership of the completed skb to the PTP worker.\\nThe skb should not be used afterwards, as the worker may\\nrun before the rest of our code and free the skb, leading\\nto a use-after-free.\\n\\nSince dev_kfree_skb_any() accepts NULL make the loss of\\nownership more obvious and set skb to NULL.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.71\", \"versionStartIncluding\": \"5.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.19.12\", \"versionStartIncluding\": \"5.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.0\", \"versionStartIncluding\": \"5.14\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T08:51:36.351Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2022-48637\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T08:51:36.351Z\", \"dateReserved\": \"2024-02-25T13:44:28.315Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-04-28T12:59:33.285Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…