CVE-2022-49258

In the Linux kernel, the following vulnerability has been resolved: crypto: ccree - Fix use after free in cc_cipher_exit() kfree_sensitive(ctx_p->user.key) will free the ctx_p->user.key. But ctx_p->user.key is still used in the next line, which will lead to a use after free. We can call kfree_sensitive() after dev_dbg() to avoid the uaf.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

25 Mar 2025, 15:23

Type Values Removed Values Added
First Time Linux
Linux linux Kernel
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: crypto: ccree - Se corrige el uso después de liberación en cc_cipher_exit() kfree_sensitive(ctx_p-&gtuser.key) liberará ctx_p-&gtuser.key. Pero ctx_p-&gtuser.key aún se usa en la siguiente línea, lo que provocará un uso después de liberación. Podemos llamar a kfree_sensitive() después de dev_dbg() para evitar el uaf.
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/25c358efee5153dfd240d4e0d3169d5bebe9cacd - () https://git.kernel.org/stable/c/25c358efee5153dfd240d4e0d3169d5bebe9cacd - Patch
References () https://git.kernel.org/stable/c/335bf1fc74f775a8255257aa3e33763f2257b676 - () https://git.kernel.org/stable/c/335bf1fc74f775a8255257aa3e33763f2257b676 - Patch
References () https://git.kernel.org/stable/c/3d950c34074ed74d2713c3856ba01264523289e6 - () https://git.kernel.org/stable/c/3d950c34074ed74d2713c3856ba01264523289e6 - Patch
References () https://git.kernel.org/stable/c/c93017c8d5ebf55a4e453ac7c84cc84cf92ab570 - () https://git.kernel.org/stable/c/c93017c8d5ebf55a4e453ac7c84cc84cf92ab570 - Patch
References () https://git.kernel.org/stable/c/cffb5382bd8d3cf21b874ab5b84bf7618932286b - () https://git.kernel.org/stable/c/cffb5382bd8d3cf21b874ab5b84bf7618932286b - Patch

27 Feb 2025, 18:15

Type Values Removed Values Added
CWE CWE-416
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

26 Feb 2025, 07:01

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 07:01

Updated : 2025-03-25 15:23


NVD link : CVE-2022-49258

Mitre link : CVE-2022-49258

CVE.ORG link : CVE-2022-49258


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free