We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-48748

net: bridge: vlan: fix memory leak in __allowed_ingress



AssignerLinux
Reserved2024-06-20
Published2024-06-20
Updated2024-08-03

Description

In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state, if vlan snooping and stats are disabled, untagged or priority-tagged ingress frame will go to check pvid state. If the port state is forwarding and the pvid state is not learning/forwarding, untagged or priority-tagged frame will be dropped but skb memory is not freed. Should free skb when __allowed_ingress returns false.

Product status

Default status
unaffected

a580c76d534c before 446ff1fc37c7
affected

a580c76d534c before c5e216e880fa
affected

a580c76d534c before 14be8d448fca
affected

a580c76d534c before fd20d9738395
affected

Default status
affected

5.6
affected

Any version before 5.6
unaffected

5.10.96
unaffected

5.15.19
unaffected

5.16.5
unaffected

5.17
unaffected

References

https://git.kernel.org/stable/c/446ff1fc37c74093e81db40811a07b5a19f1d797

https://git.kernel.org/stable/c/c5e216e880fa6f2cd9d4a6541269377657163098

https://git.kernel.org/stable/c/14be8d448fca6fe7b2a413831eedd55aef6c6511

https://git.kernel.org/stable/c/fd20d9738395cf8e27d0a17eba34169699fccdff

cve.org CVE-2022-48748

nvd.nist.gov CVE-2022-48748

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.