[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2022-48674":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T08:53:30.047Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":46,"related":47,"reserved_at":9,"published_at":51,"modified_at":52,"state":53,"summary":54,"references_raw":63,"kevs":78,"epss":79,"epss_history":82,"metrics":322,"affected":335},"CVE-2022-48674","In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix pcluster use-after-free on UP platforms\n\nDuring stress testing with CONFIG_SMP disabled, KASAN reports as below:\n\n==================================================================\nBUG: KASAN: use-after-free in __mutex_lock+0xe5/0xc30\nRead of size 8 at addr ffff8881094223f8 by task stress/7789\n\nCPU: 0 PID: 7789 Comm: stress Not tainted 6.0.0-rc1-00002-g0d53d2e882f9 #3\nHardware name: Red Hat KVM, BIOS 0.5.1 01/01/2011\nCall Trace:\n \u003CTASK>\n..\n __mutex_lock+0xe5/0xc30\n..\n z_erofs_do_read_page+0x8ce/0x1560\n..\n z_erofs_readahead+0x31c/0x580\n..\nFreed by task 7787\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x20/0x30\n kasan_set_free_info+0x20/0x40\n __kasan_slab_free+0x10c/0x190\n kmem_cache_free+0xed/0x380\n rcu_core+0x3d5/0xc90\n __do_softirq+0x12d/0x389\n\nLast potentially related work creation:\n kasan_save_stack+0x1e/0x40\n __kasan_record_aux_stack+0x97/0xb0\n call_rcu+0x3d/0x3f0\n erofs_shrink_workstation+0x11f/0x210\n erofs_shrink_scan+0xdc/0x170\n shrink_slab.constprop.0+0x296/0x530\n drop_slab+0x1c/0x70\n drop_caches_sysctl_handler+0x70/0x80\n proc_sys_call_handler+0x20a/0x2f0\n vfs_write+0x555/0x6c0\n ksys_write+0xbe/0x160\n do_syscall_64+0x3b/0x90\n\nThe root cause is that erofs_workgroup_unfreeze() doesn't reset to\norig_val thus it causes a race that the pcluster reuses unexpectedly\nbefore freeing.\n\nSince UP platforms are quite rare now, such path becomes unnecessary.\nLet's drop such specific-designed path directly instead.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-416","Use After Free","The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory \"belongs\" to the code that operates on the new pointer.","weakness","Stable","Variant","High",[],[],[],[],[24,26,28,30,32,34,36,38,40,42,44],{"_key":25},"SUSE-SU-2024:4364-1",{"_key":27},"SUSE-SU-2024:4315-1",{"_key":29},"SUSE-SU-2024:4376-1",{"_key":31},"DEBIAN-CVE-2022-48674",{"_key":33},"UBUNTU-CVE-2022-48674",{"_key":35},"USN-6951-1",{"_key":37},"USN-6951-2",{"_key":39},"USN-6951-3",{"_key":41},"USN-6951-4",{"_key":43},"USN-6953-1",{"_key":45},"USN-6979-1",[],[48,49,50],{"_key":25},{"_key":27},{"_key":29},"2024-05-03T14:51:57.294Z","2026-05-23T15:20:29.799Z","Analyzed",{"cisa_kev":55,"cisa_ransomware":55,"cisa_vendor":9,"epss_severity":56,"epss_score":57,"severity":58,"severity_score":59,"severity_version":60,"severity_source":61,"severity_vector":62,"severity_status":53},false,"low",0.00016,"high",7.8,"v3.1","nvd","CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",[64,70,74],{"url":65,"sources":66,"tags":68},"https://git.kernel.org/stable/c/8ddd001cef5e82d19192e6861068463ecca5f556",[67,61],"cve.org",[69],"Patch",{"url":71,"sources":72,"tags":73},"https://git.kernel.org/stable/c/94c34faaafe7b55adc2d8d881db195b646959b9e",[67,61],[69],{"url":75,"sources":76,"tags":77},"https://git.kernel.org/stable/c/2f44013e39984c127c6efedf70e6b5f4e9dcf315",[67,61],[69],[],{"date":80,"score":57,"percentile":81},"2026-06-03",0.03634,[83,87,90,93,96,99,101,103,105,108,111,114,116,118,120,124,127,130,133,136,139,141,144,147,150,153,156,159,161,164,167,170,173,176,178,181,184,187,190,192,194,196,199,202,205,207,209,211,214,217,219,222,225,228,231,233,235,237,240,242,244,247,249,251,253,255,257,260,263,266,268,270,273,275,278,280,283,285,287,290,292,295,298,301,304,307,310,313,316,319],{"date":84,"score":85,"percentile":86},"2025-11-04",0.00009,0.00656,{"date":88,"score":85,"percentile":89},"2025-11-05",0.00657,{"date":91,"score":85,"percentile":92},"2025-11-06",0.00659,{"date":94,"score":85,"percentile":95},"2025-11-07",0.00662,{"date":97,"score":85,"percentile":98},"2025-11-08",0.0066,{"date":100,"score":85,"percentile":98},"2025-11-09",{"date":102,"score":85,"percentile":86},"2025-11-10",{"date":104,"score":85,"percentile":86},"2025-11-11",{"date":106,"score":85,"percentile":107},"2025-11-12",0.00653,{"date":109,"score":85,"percentile":110},"2025-11-13",0.00651,{"date":112,"score":85,"percentile":113},"2025-11-14",0.00655,{"date":115,"score":85,"percentile":92},"2025-11-15",{"date":117,"score":85,"percentile":92},"2025-11-16",{"date":119,"score":85,"percentile":89},"2025-11-17",{"date":121,"score":122,"percentile":123},"2025-11-18",0.00091,0.2188,{"date":125,"score":122,"percentile":126},"2025-11-19",0.21892,{"date":128,"score":122,"percentile":129},"2025-11-20",0.219,{"date":131,"score":85,"percentile":132},"2025-11-21",0.00671,{"date":134,"score":85,"percentile":135},"2025-11-22",0.0067,{"date":137,"score":85,"percentile":138},"2025-11-23",0.00664,{"date":140,"score":85,"percentile":92},"2025-11-24",{"date":142,"score":85,"percentile":143},"2025-11-25",0.00658,{"date":145,"score":85,"percentile":146},"2025-11-26",0.00649,{"date":148,"score":85,"percentile":149},"2025-11-27",0.00648,{"date":151,"score":85,"percentile":152},"2025-11-28",0.00652,{"date":154,"score":85,"percentile":155},"2025-11-29",0.00667,{"date":157,"score":85,"percentile":158},"2025-11-30",0.00669,{"date":160,"score":85,"percentile":132},"2025-12-01",{"date":162,"score":85,"percentile":163},"2025-12-02",0.00668,{"date":165,"score":85,"percentile":166},"2025-12-03",0.00674,{"date":168,"score":85,"percentile":169},"2025-12-04",0.00675,{"date":171,"score":85,"percentile":172},"2025-12-05",0.00682,{"date":174,"score":85,"percentile":175},"2025-12-06",0.0068,{"date":177,"score":85,"percentile":175},"2025-12-07",{"date":179,"score":85,"percentile":180},"2025-12-08",0.00684,{"date":182,"score":85,"percentile":183},"2025-12-09",0.00697,{"date":185,"score":85,"percentile":186},"2025-12-10",0.00709,{"date":188,"score":85,"percentile":189},"2025-12-11",0.00707,{"date":191,"score":85,"percentile":186},"2025-12-12",{"date":193,"score":85,"percentile":189},"2025-12-13",{"date":195,"score":85,"percentile":189},"2025-12-14",{"date":197,"score":85,"percentile":198},"2025-12-15",0.00701,{"date":200,"score":85,"percentile":201},"2025-12-16",0.00704,{"date":203,"score":85,"percentile":204},"2025-12-17",0.00706,{"date":206,"score":85,"percentile":204},"2025-12-18",{"date":208,"score":85,"percentile":186},"2025-12-19",{"date":210,"score":85,"percentile":186},"2025-12-20",{"date":212,"score":85,"percentile":213},"2025-12-21",0.00705,{"date":215,"score":85,"percentile":216},"2025-12-22",0.00708,{"date":218,"score":85,"percentile":189},"2025-12-23",{"date":220,"score":85,"percentile":221},"2025-12-24",0.0071,{"date":223,"score":85,"percentile":224},"2025-12-25",0.00711,{"date":226,"score":85,"percentile":227},"2025-12-26",0.00716,{"date":229,"score":85,"percentile":230},"2025-12-27",0.00712,{"date":232,"score":85,"percentile":230},"2025-12-28",{"date":234,"score":85,"percentile":221},"2025-12-29",{"date":236,"score":85,"percentile":189},"2025-12-30",{"date":238,"score":85,"percentile":239},"2025-12-31",0.00703,{"date":241,"score":85,"percentile":204},"2026-01-01",{"date":243,"score":85,"percentile":230},"2026-01-02",{"date":245,"score":85,"percentile":246},"2026-01-03",0.00713,{"date":248,"score":85,"percentile":213},"2026-01-04",{"date":250,"score":85,"percentile":216},"2026-01-05",{"date":252,"score":85,"percentile":189},"2026-01-06",{"date":254,"score":85,"percentile":213},"2026-01-07",{"date":256,"score":85,"percentile":221},"2026-01-08",{"date":258,"score":85,"percentile":259},"2026-01-09",0.00717,{"date":261,"score":85,"percentile":262},"2026-01-10",0.0072,{"date":264,"score":85,"percentile":265},"2026-01-11",0.00719,{"date":267,"score":85,"percentile":259},"2026-01-12",{"date":269,"score":85,"percentile":227},"2026-01-13",{"date":271,"score":85,"percentile":272},"2026-01-14",0.00715,{"date":274,"score":85,"percentile":259},"2026-01-15",{"date":276,"score":85,"percentile":277},"2026-01-16",0.00718,{"date":279,"score":85,"percentile":277},"2026-01-17",{"date":281,"score":85,"percentile":282},"2026-01-18",0.00722,{"date":284,"score":85,"percentile":265},"2026-01-19",{"date":286,"score":85,"percentile":227},"2026-01-20",{"date":288,"score":85,"percentile":289},"2026-01-21",0.00714,{"date":291,"score":85,"percentile":272},"2026-01-22",{"date":293,"score":85,"percentile":294},"2026-01-23",0.00724,{"date":296,"score":85,"percentile":297},"2026-01-24",0.00728,{"date":299,"score":85,"percentile":300},"2026-01-25",0.00729,{"date":302,"score":85,"percentile":303},"2026-01-26",0.0073,{"date":305,"score":57,"percentile":306},"2026-01-27",0.02619,{"date":308,"score":57,"percentile":309},"2026-01-28",0.02622,{"date":311,"score":57,"percentile":312},"2026-01-29",0.02644,{"date":314,"score":57,"percentile":315},"2026-01-30",0.0265,{"date":317,"score":57,"percentile":318},"2026-01-31",0.02671,{"date":320,"score":57,"percentile":321},"2026-02-01",0.02725,[323,330],{"source":67,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":324,"cvss_v4_0":9},{"baseScore":325,"baseSeverity":326,"vectorString":327,"impactScore":328,"exploitabilityScore":329},6.2,"MEDIUM","CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",6,6.4,{"source":61,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":331,"cvss_v4_0":9},{"baseScore":59,"baseSeverity":332,"vectorString":62,"impactScore":333,"exploitabilityScore":334},"HIGH",9.8,4.6,[336,368],{"ecosystem":9,"name":337,"vendor":338,"product":338,"cpe_part":339,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":340},"Linux","linux","a",[341,348,351,354,356,358,362,366],{"version":342,"is_range":343,"range_type":67,"version_start":344,"version_start_type":345,"version_end":346,"version_end_type":347,"fixed_in":9},">= 73f5c66df3e26ab750cefcb9a3e08c71c9f79cad, \u003C 8ddd001cef5e82d19192e6861068463ecca5f556",true,"73f5c66df3e26ab750cefcb9a3e08c71c9f79cad","including","8ddd001cef5e82d19192e6861068463ecca5f556","excluding",{"version":349,"is_range":343,"range_type":67,"version_start":344,"version_start_type":345,"version_end":350,"version_end_type":347,"fixed_in":9},">= 73f5c66df3e26ab750cefcb9a3e08c71c9f79cad, \u003C 94c34faaafe7b55adc2d8d881db195b646959b9e","94c34faaafe7b55adc2d8d881db195b646959b9e",{"version":352,"is_range":343,"range_type":67,"version_start":344,"version_start_type":345,"version_end":353,"version_end_type":347,"fixed_in":9},">= 73f5c66df3e26ab750cefcb9a3e08c71c9f79cad, \u003C 2f44013e39984c127c6efedf70e6b5f4e9dcf315","2f44013e39984c127c6efedf70e6b5f4e9dcf315",{"version":355,"is_range":55,"range_type":67,"version_start":355,"version_start_type":345,"version_end":355,"version_end_type":345,"fixed_in":9},"08ec9e6892cc792d7f8fe4d13bd8a0e91fb23488",{"version":357,"is_range":55,"range_type":67,"version_start":357,"version_start_type":345,"version_end":357,"version_end_type":345,"fixed_in":9},"78c46113413bea1cc345757112aa2642e0f66de5",{"version":359,"is_range":343,"range_type":67,"version_start":360,"version_start_type":345,"version_end":361,"version_end_type":347,"fixed_in":9},">= 4.19.26, \u003C 4.20","4.19.26","4.20",{"version":363,"is_range":343,"range_type":67,"version_start":364,"version_start_type":345,"version_end":365,"version_end_type":347,"fixed_in":9},">= 4.20.13, \u003C 4.21","4.20.13","4.21",{"version":367,"is_range":55,"range_type":67,"version_start":367,"version_start_type":345,"version_end":367,"version_end_type":345,"fixed_in":9},"5.0",{"ecosystem":9,"name":369,"vendor":338,"product":370,"cpe_part":371,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":372},"linux kernel","linux_kernel","o",[373,376,379,383,385,387,389],{"version":374,"is_range":343,"range_type":375,"version_start":360,"version_start_type":345,"version_end":361,"version_end_type":347,"fixed_in":9},"gte4.19.26_lt4.20","cpe",{"version":377,"is_range":343,"range_type":375,"version_start":364,"version_start_type":345,"version_end":378,"version_end_type":347,"fixed_in":9},"gte4.20.13_lt5.15.68","5.15.68",{"version":380,"is_range":343,"range_type":375,"version_start":381,"version_start_type":345,"version_end":382,"version_end_type":347,"fixed_in":9},"gte5.16_lt5.19.9","5.16","5.19.9",{"version":384,"is_range":55,"range_type":375,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.0:rc1",{"version":386,"is_range":55,"range_type":375,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.0:rc2",{"version":388,"is_range":55,"range_type":375,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.0:rc3",{"version":390,"is_range":55,"range_type":375,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.0:rc4"]