← All CVEs

CVE-2022-49770

critical · 9.8

In the Linux kernel, the following vulnerability has been resolved: ceph: avoid putting the realm twice when decoding snaps fails When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprealm memory. And then it'll put it twice and could cause random use-after-free, BUG_ON, etc issues.

9.8
CVSS
0.6%
EPSS (exploit prob.)
45th
EPSS percentile
2025-05-01
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-416

Affected products

VendorProductAffected versions
linuxlinux_kernel>= 2.6.35, < 4.19.268
linuxlinux_kernel>= 4.20, < 5.4.226
linuxlinux_kernel>= 5.5, < 5.10.157
linuxlinux_kernel>= 5.11, < 5.15.81
linuxlinux_kernel>= 5.16, < 6.0.10
linuxlinux_kernel2.6.34
linuxlinux_kernel2.6.34
linuxlinux_kernel2.6.34
linuxlinux_kernel2.6.34
linuxlinux_kernel2.6.34
linuxlinux_kernel2.6.34
linuxlinux_kernel2.6.34
linuxlinux_kernel6.1
linuxlinux_kernel6.1
linuxlinux_kernel6.1
linuxlinux_kernel6.1
linuxlinux_kernel6.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-49770