CVE Database
/

CVE-2022-49258

Back to search

CVE-2022-49258

Published: Feb 26, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: ccree - Fix use after free in cc_cipher_exit() kfree_sensitive(ctx_p->user.key) will free the ctx_p->user.key. But ctx_p->user.key is still used in the next line, which will lead to a use after free. We can call kfree_sensitive() after dev_dbg() to avoid the uaf.

VendorProductVersions

Linux

Linux

affected
63ee04c8b491ee148489347e7da9fbfd982ca2bb - < c93017c8d5ebf55a4e453ac7c84cc84cf92ab570
affected
63ee04c8b491ee148489347e7da9fbfd982ca2bb - < 335bf1fc74f775a8255257aa3e33763f2257b676
affected
63ee04c8b491ee148489347e7da9fbfd982ca2bb - < 25c358efee5153dfd240d4e0d3169d5bebe9cacd
affected
63ee04c8b491ee148489347e7da9fbfd982ca2bb - < cffb5382bd8d3cf21b874ab5b84bf7618932286b
affected
63ee04c8b491ee148489347e7da9fbfd982ca2bb - < 3d950c34074ed74d2713c3856ba01264523289e6

Linux

Linux

affected
4.17
unaffected
0 - < 4.17
unaffected
5.10.110 - <= 5.10.*
unaffected
5.15.33 - <= 5.15.*
unaffected
5.16.19 - <= 5.16.*

+2 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now