CVE-2022-48787 (GCVE-0-2022-48787)
Vulnerability from cvelistv5
Published
2024-07-16 11:43
Modified
2026-08-05 08:52
Summary
In the Linux kernel, the following vulnerability has been resolved: iwlwifi: fix use-after-free If no firmware was present at all (or, presumably, all of the firmware files failed to parse), we end up unbinding by calling device_release_driver(), which calls remove(), which then in iwlwifi calls iwl_drv_stop(), freeing the 'drv' struct. However the new code I added will still erroneously access it after it was freed. Set 'failure=false' in this case to avoid the access, all data was already freed anyway.
Impacted products
Vendor Product Version
Linux Linux Version: 8e10749fa1a454c1e7214f36cec83241f5a36ef1
Version: 1d7cc54137a4f28506dc7beac235b240b08f4e59
Version: 0446cafa843e6db4982731c167e11c80d42be7e2
Version: febab6b60d61d13cd9f30a2991deea56df39567d
Version: e23f075d77987de4215c8e0696f28bcc707506f7
Version: 6b5ad4bd0d78fef6bbe0ecdf96e09237c9c52cc1
Version: ab07506b0454bea606095951e19e72c282bfbb42
Create a notification for this product.
   Linux Linux Version: 4.14.263   
Version: 4.19.226   
Version: 5.4.174   
Version: 5.10.94   
Version: 5.15.17   
Version: 5.16.3   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T15:25:01.764Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/d3b98fe36f8a06ce654049540773256ab59cb53d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/7d6475179b85a83186ccce59cdc359d4f07d0bcb"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/494de920d98f125b099f27a2d274850750aff957"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/008508c16af0087cda0394e1ac6f0493b01b6063"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/ddd46059f7d99119b62d44c519df7a79f2e6a515"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/9958b9cbb22145295ee1ffaea0904c383da2c05d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/bea2662e7818e15d7607d17d57912ac984275d94"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-48787",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T16:59:49.027467Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:34:16.166Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/wireless/intel/iwlwifi/iwl-drv.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "d3b98fe36f8a06ce654049540773256ab59cb53d",
              "status": "affected",
              "version": "8e10749fa1a454c1e7214f36cec83241f5a36ef1",
              "versionType": "git"
            },
            {
              "lessThan": "7d6475179b85a83186ccce59cdc359d4f07d0bcb",
              "status": "affected",
              "version": "1d7cc54137a4f28506dc7beac235b240b08f4e59",
              "versionType": "git"
            },
            {
              "lessThan": "494de920d98f125b099f27a2d274850750aff957",
              "status": "affected",
              "version": "0446cafa843e6db4982731c167e11c80d42be7e2",
              "versionType": "git"
            },
            {
              "lessThan": "008508c16af0087cda0394e1ac6f0493b01b6063",
              "status": "affected",
              "version": "febab6b60d61d13cd9f30a2991deea56df39567d",
              "versionType": "git"
            },
            {
              "lessThan": "ddd46059f7d99119b62d44c519df7a79f2e6a515",
              "status": "affected",
              "version": "e23f075d77987de4215c8e0696f28bcc707506f7",
              "versionType": "git"
            },
            {
              "lessThan": "9958b9cbb22145295ee1ffaea0904c383da2c05d",
              "status": "affected",
              "version": "6b5ad4bd0d78fef6bbe0ecdf96e09237c9c52cc1",
              "versionType": "git"
            },
            {
              "lessThan": "bea2662e7818e15d7607d17d57912ac984275d94",
              "status": "affected",
              "version": "ab07506b0454bea606095951e19e72c282bfbb42",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/wireless/intel/iwlwifi/iwl-drv.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "4.14.268",
              "status": "affected",
              "version": "4.14.263",
              "versionType": "semver"
            },
            {
              "lessThan": "4.19.231",
              "status": "affected",
              "version": "4.19.226",
              "versionType": "semver"
            },
            {
              "lessThan": "5.4.181",
              "status": "affected",
              "version": "5.4.174",
              "versionType": "semver"
            },
            {
              "lessThan": "5.10.102",
              "status": "affected",
              "version": "5.10.94",
              "versionType": "semver"
            },
            {
              "lessThan": "5.15.25",
              "status": "affected",
              "version": "5.15.17",
              "versionType": "semver"
            },
            {
              "lessThan": "5.16.11",
              "status": "affected",
              "version": "5.16.3",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.14.268",
                  "versionStartIncluding": "4.14.263",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.231",
                  "versionStartIncluding": "4.19.226",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.181",
                  "versionStartIncluding": "5.4.174",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.102",
                  "versionStartIncluding": "5.10.94",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.25",
                  "versionStartIncluding": "5.15.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.16.11",
                  "versionStartIncluding": "5.16.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niwlwifi: fix use-after-free\n\nIf no firmware was present at all (or, presumably, all of the\nfirmware files failed to parse), we end up unbinding by calling\ndevice_release_driver(), which calls remove(), which then in\niwlwifi calls iwl_drv_stop(), freeing the \u0027drv\u0027 struct. However\nthe new code I added will still erroneously access it after it\nwas freed.\n\nSet \u0027failure=false\u0027 in this case to avoid the access, all data\nwas already freed anyway."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The UAF is in the iwlwifi firmware-request callback during PCI probe/unbind, reached via local driver initialization and request_firmware_nowait\u2014not via WiFi frame processing or any network-facing path.\nAC:L - Once the failure/unbind path runs, the UAF is deterministic (device_release_driver frees drv, then iwl_dealloc_ucode uses it); no attacker-uncontrollable race is required to hit the bug.\nPR:L - A local unprivileged user on a system with Intel WiFi can be present when the driver probes with missing or unparseable firmware (common deployment failure mode), which is sufficient to reach the vulnerable path without needing real root beyond basic local access.\nUI:N - Firmware load and the subsequent unbind/UAF occur automatically in the async firmware callback during driver probe; no separate victim user action is required.\nS:U - This is a standard in-kernel UAF in the WiFi driver affecting the host kernel\u0027s own memory authority, with no VM escape, IOMMU bypass, or other cross-boundary impact.\nC:H - Use-after-free of struct iwl_drv lets an attacker reclaim the object and control fields later read as pointers, enabling disclosure of kernel memory contents.\nI:H - iwl_dealloc_ucode() performs multiple kfree() calls and a memset on the freed drv-\u003efw state, yielding arbitrary-free and memory-corruption primitives suitable for control-flow hijacking.\nA:H - Dereferencing and freeing poisoned/reused slab contents reliably causes kernel oops/panic, as confirmed by multiple real-world crash reports that motivated the fix."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T08:52:17.446Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d3b98fe36f8a06ce654049540773256ab59cb53d"
        },
        {
          "url": "https://git.kernel.org/stable/c/7d6475179b85a83186ccce59cdc359d4f07d0bcb"
        },
        {
          "url": "https://git.kernel.org/stable/c/494de920d98f125b099f27a2d274850750aff957"
        },
        {
          "url": "https://git.kernel.org/stable/c/008508c16af0087cda0394e1ac6f0493b01b6063"
        },
        {
          "url": "https://git.kernel.org/stable/c/ddd46059f7d99119b62d44c519df7a79f2e6a515"
        },
        {
          "url": "https://git.kernel.org/stable/c/9958b9cbb22145295ee1ffaea0904c383da2c05d"
        },
        {
          "url": "https://git.kernel.org/stable/c/bea2662e7818e15d7607d17d57912ac984275d94"
        }
      ],
      "title": "iwlwifi: fix use-after-free",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2022-48787",
    "datePublished": "2024-07-16T11:43:44.349Z",
    "dateReserved": "2024-07-16T11:38:08.891Z",
    "dateUpdated": "2026-08-05T08:52:17.446Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/d3b98fe36f8a06ce654049540773256ab59cb53d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/7d6475179b85a83186ccce59cdc359d4f07d0bcb\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/494de920d98f125b099f27a2d274850750aff957\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/008508c16af0087cda0394e1ac6f0493b01b6063\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/ddd46059f7d99119b62d44c519df7a79f2e6a515\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/9958b9cbb22145295ee1ffaea0904c383da2c05d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/bea2662e7818e15d7607d17d57912ac984275d94\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-03T15:25:01.764Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2022-48787\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T16:59:49.027467Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:21.690Z\"}}], \"cna\": {\"title\": \"iwlwifi: fix use-after-free\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The UAF is in the iwlwifi firmware-request callback during PCI probe/unbind, reached via local driver initialization and request_firmware_nowait\\u2014not via WiFi frame processing or any network-facing path.\\nAC:L - Once the failure/unbind path runs, the UAF is deterministic (device_release_driver frees drv, then iwl_dealloc_ucode uses it); no attacker-uncontrollable race is required to hit the bug.\\nPR:L - A local unprivileged user on a system with Intel WiFi can be present when the driver probes with missing or unparseable firmware (common deployment failure mode), which is sufficient to reach the vulnerable path without needing real root beyond basic local access.\\nUI:N - Firmware load and the subsequent unbind/UAF occur automatically in the async firmware callback during driver probe; no separate victim user action is required.\\nS:U - This is a standard in-kernel UAF in the WiFi driver affecting the host kernel\u0027s own memory authority, with no VM escape, IOMMU bypass, or other cross-boundary impact.\\nC:H - Use-after-free of struct iwl_drv lets an attacker reclaim the object and control fields later read as pointers, enabling disclosure of kernel memory contents.\\nI:H - iwl_dealloc_ucode() performs multiple kfree() calls and a memset on the freed drv-\u003efw state, yielding arbitrary-free and memory-corruption primitives suitable for control-flow hijacking.\\nA:H - Dereferencing and freeing poisoned/reused slab contents reliably causes kernel oops/panic, as confirmed by multiple real-world crash reports that motivated the fix.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"8e10749fa1a454c1e7214f36cec83241f5a36ef1\", \"lessThan\": \"d3b98fe36f8a06ce654049540773256ab59cb53d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"1d7cc54137a4f28506dc7beac235b240b08f4e59\", \"lessThan\": \"7d6475179b85a83186ccce59cdc359d4f07d0bcb\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0446cafa843e6db4982731c167e11c80d42be7e2\", \"lessThan\": \"494de920d98f125b099f27a2d274850750aff957\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"febab6b60d61d13cd9f30a2991deea56df39567d\", \"lessThan\": \"008508c16af0087cda0394e1ac6f0493b01b6063\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"e23f075d77987de4215c8e0696f28bcc707506f7\", \"lessThan\": \"ddd46059f7d99119b62d44c519df7a79f2e6a515\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6b5ad4bd0d78fef6bbe0ecdf96e09237c9c52cc1\", \"lessThan\": \"9958b9cbb22145295ee1ffaea0904c383da2c05d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"ab07506b0454bea606095951e19e72c282bfbb42\", \"lessThan\": \"bea2662e7818e15d7607d17d57912ac984275d94\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/net/wireless/intel/iwlwifi/iwl-drv.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.14.263\", \"lessThan\": \"4.14.268\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"4.19.226\", \"lessThan\": \"4.19.231\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.4.174\", \"lessThan\": \"5.4.181\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.10.94\", \"lessThan\": \"5.10.102\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.15.17\", \"lessThan\": \"5.15.25\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.16.3\", \"lessThan\": \"5.16.11\", \"versionType\": \"semver\"}], \"programFiles\": [\"drivers/net/wireless/intel/iwlwifi/iwl-drv.c\"], \"defaultStatus\": \"unaffected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/d3b98fe36f8a06ce654049540773256ab59cb53d\"}, {\"url\": \"https://git.kernel.org/stable/c/7d6475179b85a83186ccce59cdc359d4f07d0bcb\"}, {\"url\": \"https://git.kernel.org/stable/c/494de920d98f125b099f27a2d274850750aff957\"}, {\"url\": \"https://git.kernel.org/stable/c/008508c16af0087cda0394e1ac6f0493b01b6063\"}, {\"url\": \"https://git.kernel.org/stable/c/ddd46059f7d99119b62d44c519df7a79f2e6a515\"}, {\"url\": \"https://git.kernel.org/stable/c/9958b9cbb22145295ee1ffaea0904c383da2c05d\"}, {\"url\": \"https://git.kernel.org/stable/c/bea2662e7818e15d7607d17d57912ac984275d94\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\niwlwifi: fix use-after-free\\n\\nIf no firmware was present at all (or, presumably, all of the\\nfirmware files failed to parse), we end up unbinding by calling\\ndevice_release_driver(), which calls remove(), which then in\\niwlwifi calls iwl_drv_stop(), freeing the \u0027drv\u0027 struct. However\\nthe new code I added will still erroneously access it after it\\nwas freed.\\n\\nSet \u0027failure=false\u0027 in this case to avoid the access, all data\\nwas already freed anyway.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.14.268\", \"versionStartIncluding\": \"4.14.263\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.19.231\", \"versionStartIncluding\": \"4.19.226\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.181\", \"versionStartIncluding\": \"5.4.174\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.102\", \"versionStartIncluding\": \"5.10.94\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.25\", \"versionStartIncluding\": \"5.15.17\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.16.11\", \"versionStartIncluding\": \"5.16.3\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T08:52:17.446Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2022-48787\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T08:52:17.446Z\", \"dateReserved\": \"2024-07-16T11:38:08.891Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-07-16T11:43:44.349Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…