Bugzilla – Bug 1205760
VUL-0: CVE-2022-45886: kernel-source-rt,kernel-source,kernel-source-azure: UaF in drivers/media/dvb-core/dvb_net.c
Last modified: 2023-03-24 13:02:40 UTC
CVE-2022-45886 An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_net.c has a .disconnect versus dvb_device_open race condition that leads to a use-after-free. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-45886 https://www.cve.org/CVERecord?id=CVE-2022-45886 https://lore.kernel.org/linux-media/20221115131822.6640-3-imv4bel@gmail.com/ https://lore.kernel.org/linux-media/20221115131822.6640-1-imv4bel@gmail.com/
Let's wait for the upstream review and acceptance.
I pinged the reporter for verifying with the latest tree in a few weeks ago, but no reply, so far.