{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2022-48637","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-02-25T13:44:28.315Z","datePublished":"2024-04-28T12:59:33.285Z","dateUpdated":"2026-08-05T08:51:36.351Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T08:51:36.351Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt: prevent skb UAF after handing over to PTP worker\n\nWhen reading the timestamp is required bnxt_tx_int() hands\nover the ownership of the completed skb to the PTP worker.\nThe skb should not be used afterwards, as the worker may\nrun before the rest of our code and free the skb, leading\nto a use-after-free.\n\nSince dev_kfree_skb_any() accepts NULL make the loss of\nownership more obvious and set skb to NULL."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in the bnxt TX completion/NAPI path and is only reached when a local process transmits PTP packets with hardware TX timestamping; a remote peer cannot trigger this via received packets alone.\nAC:L - An attacker who can send timestamped PTP frames repeatedly triggers the handoff to the PTP worker; per UAF guidance and the rule to prefer higher severity when uncertain, this is Low complexity rather than depending on uncontrolled conditions.\nPR:L - With device TX hwtstamp already enabled (typical under ptp4l), an unprivileged user can set SO_TIMESTAMPING_TX_HARDWARE and send UDP PTP event packets (port 319) with no further capabilities.\nUI:N - Exploitation requires no victim action beyond the attacker sending the crafted/timestamp-requested packets on the local system.\nS:U - Impact is confined to the same kernel privilege domain as the vulnerable driver; this is standard in-kernel memory corruption, not a cross-boundary escape.\nC:H - This is a use-after-free on an skb after the PTP worker may free it, which per kernel CVSS guidance enables high confidentiality impact via control of the freed object.\nI:H - The same skb UAF is treatable as a heap corruption primitive enabling arbitrary write/control-flow impact under standard UAF exploitation assumptions.\nA:H - Use-after-free of the skb can cause kernel oops/panic or otherwise deny service when the dangling pointer is accessed after free."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/broadcom/bnxt/bnxt.c"],"versions":[{"version":"83bb623c968e7351aee5111547693f95f330dc5a","lessThan":"08483e4c0c83b221b8891434a04cec405dee94a6","status":"affected","versionType":"git"},{"version":"83bb623c968e7351aee5111547693f95f330dc5a","lessThan":"32afa1f23e42cc635ccf4c39f24514d03d1e8338","status":"affected","versionType":"git"},{"version":"83bb623c968e7351aee5111547693f95f330dc5a","lessThan":"c31f26c8f69f776759cbbdfb38e40ea91aa0dd65","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/broadcom/bnxt/bnxt.c"],"versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","status":"unaffected","versionType":"semver"},{"version":"5.15.71","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"5.19.12","lessThanOrEqual":"5.19.*","status":"unaffected","versionType":"semver"},{"version":"6.0","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"5.15.71"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"5.19.12"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.0"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/08483e4c0c83b221b8891434a04cec405dee94a6"},{"url":"https://git.kernel.org/stable/c/32afa1f23e42cc635ccf4c39f24514d03d1e8338"},{"url":"https://git.kernel.org/stable/c/c31f26c8f69f776759cbbdfb38e40ea91aa0dd65"}],"title":"bnxt: prevent skb UAF after handing over to PTP worker","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-416","lang":"en","description":"CWE-416 Use After Free"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-06-07T17:06:57.891405Z","id":"CVE-2022-48637","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-07T17:07:15.083Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T15:17:55.303Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/08483e4c0c83b221b8891434a04cec405dee94a6","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/32afa1f23e42cc635ccf4c39f24514d03d1e8338","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/c31f26c8f69f776759cbbdfb38e40ea91aa0dd65","tags":["x_transferred"]}]}]}}