CVE-2022-49196

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 26, 2025
Updated: Mar 4, 2025
CWE ID 416

Summary

CVE-2022-49196: A vulnerability in the Linux kernel's powerpc/pseries driver affects the remove_phb_dynamic() function. This function attempts to use the io_resource pointer of a host bridge device after calling device_unregister(), which may have already freed the device due to a release function call. If no references remain when device_unregister() is called, a use-after-free condition arises, leading to a crash. To prevent this issue, developers should maintain a reference to the host_bridge->dev until they have finished using the phb, and release the reference only after they are done.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share