Back to search
CVE-2022-49258
Published: Feb 26, 2025
Modified: May 11, 2026
PUBLISHED
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: ccree - Fix use after free in cc_cipher_exit() kfree_sensitive(ctx_p->user.key) will free the ctx_p->user.key. But ctx_p->user.key is still used in the next line, which will lead to a use after free. We can call kfree_sensitive() after dev_dbg() to avoid the uaf.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 63ee04c8b491ee148489347e7da9fbfd982ca2bb - < c93017c8d5ebf55a4e453ac7c84cc84cf92ab570affected 63ee04c8b491ee148489347e7da9fbfd982ca2bb - < 335bf1fc74f775a8255257aa3e33763f2257b676affected 63ee04c8b491ee148489347e7da9fbfd982ca2bb - < 25c358efee5153dfd240d4e0d3169d5bebe9cacdaffected 63ee04c8b491ee148489347e7da9fbfd982ca2bb - < cffb5382bd8d3cf21b874ab5b84bf7618932286baffected 63ee04c8b491ee148489347e7da9fbfd982ca2bb - < 3d950c34074ed74d2713c3856ba01264523289e6 |
Linux | Linux | affected 4.17unaffected 0 - < 4.17unaffected 5.10.110 - <= 5.10.*unaffected 5.15.33 - <= 5.15.*unaffected 5.16.19 - <= 5.16.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now