SB20250226302 - Use-after-free in Linux kernel xdp
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2022-49215)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the EXPORT_SYMBOL(), xsk_generic_xmit(), __xsk_sendmsg(), xsk_no_wakeup(), xsk_sendmsg(), xsk_recvmsg(), xsk_poll() and xsk_unbind_dev() functions in net/xdp/xsk.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/18b1ab7aa76bde181bdb1ab19a87fa9523c32f21
- https://git.kernel.org/stable/c/8a2dea162b92c322f3e42eae0c4a74b8d20aa7a9
- https://git.kernel.org/stable/c/ad7219cd8751bd258b9d1e69ae0654ec00f71875
- https://git.kernel.org/stable/c/d1579253ffce39986e7a6ab757ac93b2680a665f
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.16.19