CVE-2022-45919: Use After Free
A use-after-free in the function drivers/media/dvb-core/dvbcaen50221.c in Linux Kernel could allow a remote authenticated attacker from within the local network to cause an unknown impact.
Other sources
An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvbcaen50221.c, a use-after-free can occur is there is a disconnect after an open, because of the lack of a waitevent.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.133-1Fixed in 6.12.21-1Fixed in 6.12.22-1
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45919?
CVE-2022-45919 is classified as a medium severity vulnerability due to its potential for exploitation by remote authenticated attackers.
How do I fix CVE-2022-45919?
To mitigate CVE-2022-45919, users should upgrade the Linux kernel to a version that is newer than 6.0.10.
What systems are affected by CVE-2022-45919?
CVE-2022-45919 affects various versions of the Linux kernel between 2.6.12 and 6.0.10, as well as specific IBM Security Verify Governance components.
Can CVE-2022-45919 be exploited remotely?
CVE-2022-45919 can potentially be exploited remotely by authenticated users on the same local network.
What kind of vulnerability is CVE-2022-45919?
CVE-2022-45919 is a use-after-free vulnerability found in the Linux kernel's DVB (Digital Video Broadcasting) subsystem.