CVE-2022-48899

Source
https://cve.org/CVERecord?id=CVE-2022-48899
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48899.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-48899
Downstream
Related
Published
2024-08-21T06:10:31.936Z
Modified
2026-04-11T12:43:14.075151Z
Summary
drm/virtio: Fix GEM handle creation UAF
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/virtio: Fix GEM handle creation UAF

Userspace can guess the handle value and try to race GEM object creation with handle close, resulting in a use-after-free if we dereference the object after dropping the handle's reference. For that reason, dropping the handle's reference must be done after we are done dereferencing the object.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48899.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
62fb7a5e10962ac6ae2a2d2dbd3aedcb2a3e3257
Fixed
19ec87d06acfab2313ee82b2a689bf0c154e57ea
Fixed
d01d6d2b06c0d8390adf8f3ba08aa60b5642ef73
Fixed
68bcd063857075d2f9edfed6024387ac377923e2
Fixed
011ecdbcd520c90c344b872ca6b4821f7783b2f8
Fixed
adc48e5e408afbb01d261bd303fd9fbbbaa3e317
Fixed
52531258318ed59a2dc5a43df2eaf0eb1d65438e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48899.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.4.0
Fixed
4.19.270
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.229
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.164
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.89
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48899.json"