CVE-2022-48899: Linux Kernel
Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix GEM handle creation UAF Userspace can guess the handle value and try to race GEM object creation with handle close, resulting in a use-after-free if we dereference the object after dropping the handle's reference. For that reason, dropping the handle's reference must be done *after* we are done dereferencing the object.
Affected products
- Linux Linux Kernel: from 4.4, before 4.19.270 (fixed in 4.19.270); from 4.20, before 5.4.229 (fixed in 5.4.229); from 5.5, before 5.10.164 (fixed in 5.10.164); from 5.11, before 5.15.89 (fixed in 5.15.89); from 5.16, before 6.1.7 (fixed in 6.1.7); version 6.2 only
Published 2024-08-21. Last modified 2026-08-04.