CVE-2022-49196 is a use-after-free vulnerability in the Linux kernel's powerpc/pseries component, specifically within the remove_phb_dynamic() function. This flaw occurs when the phb object is prematurely freed after device_unregister() is called, but before subsequent operations on &phb->io_resource are completed. This can lead to system crashes, particularly when debugging tools like slub_debug and page_poison are enabled. The vulnerability is rated as High severity (CVSS 7.8), indicating that a local attacker with low privileges can exploit it with low attack complexity. Successful exploitation could lead to high confidentiality, integrity, and availability impacts, including system crashes and potential data corruption. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit modules are available. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention from the broader security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.16.39, < 3.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.7.8, < 5.15.33CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.16.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.17, < 5.17.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.16.39, < 3.17CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.