CVE-2022-48742: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: rtnetlink: make sure to refresh master_dev/m_ops in __rtnl_newlink() While looking at one unrelated syzbot bug, I found the replay logic in __rtnl_newlink() to potentially trigger use-after-free. It is better to clear master_dev and m_ops inside the loop, in case we have to replay it.

Affected products

  • Linux Linux Kernel: from 3.14, before 4.9.300 (fixed in 4.9.300); from 4.10, before 4.14.265 (fixed in 4.14.265); from 4.15, before 4.19.228 (fixed in 4.19.228); from 4.20, before 5.4.177 (fixed in 5.4.177); from 5.5, before 5.10.97 (fixed in 5.10.97); from 5.11, before 5.15.20 (fixed in 5.15.20); …

Published 2024-06-20. Last modified 2026-08-04.