CVE-2022-48873: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Don't remove map on creater_process and device_release Do not remove the map from the list on error path in fastrpc_init_create_process, instead call fastrpc_map_put, to avoid use-after-free. Do not remove it on fastrpc_device_release either, call fastrpc_map_put instead. The fastrpc_free_map is the only proper place to remove the map. This is called only after the reference count is 0.

Affected products

  • Linux Linux Kernel: from 5.2, before 5.4.230 (fixed in 5.4.230); from 5.5, before 5.10.165 (fixed in 5.10.165); from 5.11, before 5.15.90 (fixed in 5.15.90); from 5.16, before 6.1.8 (fixed in 6.1.8); version 6.2 only

Published 2024-08-21. Last modified 2026-08-04.