CVE-2022-48794: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: ieee802154: at86rf230: Stop leaking skb's Upon error the ieee802154_xmit_complete() helper is not called. Only ieee802154_wake_queue() is called manually. In the Tx case we then leak the skb structure. Free the skb structure upon error before returning when appropriate. As the 'is_tx = 0' cannot be moved in the complete handler because of a possible race between the delay in switching to STATE_RX_AACK_ON and a new interrupt, we introduce an intermediate 'was_tx' boolean just for this purpose. There is no Fixes tag applying here, many changes have been made on this area and the issue kind of always existed.

Affected products

  • Linux Linux Kernel: before 4.9.303 (fixed in 4.9.303); from 4.10, before 4.14.268 (fixed in 4.14.268); from 4.15, before 4.19.231 (fixed in 4.19.231); from 4.20, before 5.4.181 (fixed in 5.4.181); from 5.5, before 5.10.102 (fixed in 5.10.102); from 5.11, before 5.15.25 (fixed in 5.15.25); …

Published 2024-07-16. Last modified 2026-06-17.