CVE-2022-48783

high

Description

In the Linux kernel, the following vulnerability has been resolved: net: dsa: lantiq_gswip: fix use after free in gswip_remove() of_node_put(priv->ds->slave_mii_bus->dev.of_node) should be done before mdiobus_free(priv->ds->slave_mii_bus).

References

https://git.kernel.org/stable/c/f48bd34137718042872d06f2c7332b3267a29165

https://git.kernel.org/stable/c/df2495f329b08ac0d0d3e6334a01955ae839005e

https://git.kernel.org/stable/c/c61f599b8d33adfa256126a6695c734c0de331cb

https://git.kernel.org/stable/c/8c6ae46150a453f8ae9a6cd49b45f354f478587d

Details

Source: Mitre, NVD

Published: 2024-07-16

Updated: 2024-08-21

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High