CVE-2022-48872: Linux Kernel

High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix use-after-free race condition for maps It is possible that in between calling fastrpc_map_get() until map->fl->lock is taken in fastrpc_free_map(), another thread can call fastrpc_map_lookup() and get a reference to a map that is about to be deleted. Rewrite fastrpc_map_get() to only increase the reference count of a map if it's non-zero. Propagate this to callers so they can know if a map is about to be deleted. Fixes this warning: refcount_t: addition on 0; use-after-free. WARNING: CPU: 5 PID: 10100 at lib/refcount.c:25 refcount_warn_saturate ... Call trace: refcount_warn_saturate [fastrpc_map_get inlined] [fastrpc_map_lookup inlined] fastrpc_map_create fastrpc_internal_invoke fastrpc_device_ioctl __arm64_sys_ioctl invoke_syscall

Affected products

  • Linux Linux Kernel: from 5.1, before 5.4.230 (fixed in 5.4.230); from 5.5, before 5.10.165 (fixed in 5.10.165); from 5.11, before 5.15.90 (fixed in 5.15.90); from 5.16, before 6.2 (fixed in 6.2); version 6.2 only

Published 2024-08-21. Last modified 2026-08-04.