[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2022-48838":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T08:53:30.047Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":46,"related":47,"reserved_at":9,"published_at":56,"modified_at":57,"state":58,"summary":59,"references_raw":68,"kevs":103,"epss":104,"epss_history":107,"metrics":356,"affected":362},"CVE-2022-48838","In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: Fix use-after-free bug by not setting udc->dev.driver\n\nThe syzbot fuzzer found a use-after-free bug:\n\nBUG: KASAN: use-after-free in dev_uevent+0x712/0x780 drivers/base/core.c:2320\nRead of size 8 at addr ffff88802b934098 by task udevd/3689\n\nCPU: 2 PID: 3689 Comm: udevd Not tainted 5.17.0-rc4-syzkaller-00229-g4f12b742eb2b #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014\nCall Trace:\n \u003CTASK>\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\n print_address_description.constprop.0.cold+0x8d/0x303 mm/kasan/report.c:255\n __kasan_report mm/kasan/report.c:442 [inline]\n kasan_report.cold+0x83/0xdf mm/kasan/report.c:459\n dev_uevent+0x712/0x780 drivers/base/core.c:2320\n uevent_show+0x1b8/0x380 drivers/base/core.c:2391\n dev_attr_show+0x4b/0x90 drivers/base/core.c:2094\n\nAlthough the bug manifested in the driver core, the real cause was a\nrace with the gadget core.  dev_uevent() does:\n\n\tif (dev->driver)\n\t\tadd_uevent_var(env, \"DRIVER=%s\", dev->driver->name);\n\nand between the test and the dereference of dev->driver, the gadget\ncore sets dev->driver to NULL.\n\nThe race wouldn't occur if the gadget core registered its devices on\na real bus, using the standard synchronization techniques of the\ndriver core.  However, it's not necessary to make such a large change\nin order to fix this bug; all we need to do is make sure that\nudc->dev.driver is always NULL.\n\nIn fact, there is no reason for udc->dev.driver ever to be set to\nanything, let alone to the value it currently gets: the address of the\ngadget's driver.  After all, a gadget driver only knows how to manage\na gadget, not how to manage a UDC.\n\nThis patch simply removes the statements in the gadget core that touch\nudc->dev.driver.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-416","Use After Free","The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory \"belongs\" to the code that operates on the new pointer.","weakness","Stable","Variant","High",[],[],[],[],[24,26,28,30,32,34,36,38,40,42,44],{"_key":25},"SUSE-SU-2024:2894-1",{"_key":27},"SUSE-SU-2024:2902-1",{"_key":29},"SUSE-SU-2024:2929-1",{"_key":31},"SUSE-SU-2024:3225-1",{"_key":33},"SUSE-SU-2024:3249-1",{"_key":35},"SUSE-SU-2024:2939-1",{"_key":37},"SUSE-SU-2024:2947-1",{"_key":39},"SUSE-SU-2026:0473-1",{"_key":41},"DEBIAN-CVE-2022-48838",{"_key":43},"UBUNTU-CVE-2022-48838",{"_key":45},"USN-7039-1",[],[48,49,50,51,52,53,54,55],{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},"2024-07-16T12:25:09.859Z","2026-05-11T18:48:08.597Z","Modified",{"cisa_kev":60,"cisa_ransomware":60,"cisa_vendor":9,"epss_severity":61,"epss_score":62,"severity":63,"severity_score":64,"severity_version":65,"severity_source":66,"severity_vector":67,"severity_status":58},false,"low",0.00012,"medium",5.5,"v3.1","nvd","CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",[69,75,79,83,87,91,95,99],{"url":70,"sources":71,"tags":73},"https://git.kernel.org/stable/c/4325124dde6726267813c736fee61226f1d38f0b",[72,66],"cve.org",[74],"Patch",{"url":76,"sources":77,"tags":78},"https://git.kernel.org/stable/c/e2d3a7009e505e120805f449c832942660f3f7f3",[72,66],[74],{"url":80,"sources":81,"tags":82},"https://git.kernel.org/stable/c/609a7119bffe3ddd7c93f2fa65be8917e02a0b7e",[72,66],[74],{"url":84,"sources":85,"tags":86},"https://git.kernel.org/stable/c/2282a6eb6d4e118e294e43dcc421e0e0fe4040b5",[72,66],[74],{"url":88,"sources":89,"tags":90},"https://git.kernel.org/stable/c/00bdd9bf1ac6d401ad926d3d8df41b9f1399f646",[72,66],[74],{"url":92,"sources":93,"tags":94},"https://git.kernel.org/stable/c/2015c23610cd0efadaeca4d3a8d1dae9a45aa35a",[72,66],[74],{"url":96,"sources":97,"tags":98},"https://git.kernel.org/stable/c/27d64436984fb8835a8b7e95993193cc478b162e",[72,66],[74],{"url":100,"sources":101,"tags":102},"https://git.kernel.org/stable/c/16b1941eac2bd499f065a6739a40ce0011a3d740",[72,66],[74],[],{"date":105,"score":62,"percentile":106},"2026-06-03",0.01622,[108,112,115,118,121,124,127,130,133,136,139,142,145,148,151,155,158,161,164,167,170,173,176,179,182,185,188,191,194,197,200,203,206,209,211,214,217,219,221,223,226,229,232,234,236,239,242,244,247,250,253,256,258,260,262,265,268,270,272,275,277,280,283,285,287,289,292,295,297,300,303,305,307,310,313,316,319,322,325,328,331,333,336,338,340,342,344,347,350,353],{"date":109,"score":110,"percentile":111},"2025-11-04",0.00007,0.00349,{"date":113,"score":62,"percentile":114},"2025-11-05",0.01081,{"date":116,"score":62,"percentile":117},"2025-11-06",0.01092,{"date":119,"score":62,"percentile":120},"2025-11-07",0.01094,{"date":122,"score":62,"percentile":123},"2025-11-08",0.01097,{"date":125,"score":62,"percentile":126},"2025-11-09",0.01096,{"date":128,"score":62,"percentile":129},"2025-11-10",0.01087,{"date":131,"score":62,"percentile":132},"2025-11-11",0.0109,{"date":134,"score":62,"percentile":135},"2025-11-12",0.01089,{"date":137,"score":62,"percentile":138},"2025-11-13",0.01093,{"date":140,"score":62,"percentile":141},"2025-11-14",0.01107,{"date":143,"score":62,"percentile":144},"2025-11-15",0.01122,{"date":146,"score":62,"percentile":147},"2025-11-16",0.01121,{"date":149,"score":62,"percentile":150},"2025-11-17",0.01115,{"date":152,"score":153,"percentile":154},"2025-11-18",0.0009,0.21821,{"date":156,"score":153,"percentile":157},"2025-11-19",0.21833,{"date":159,"score":153,"percentile":160},"2025-11-20",0.21842,{"date":162,"score":62,"percentile":163},"2025-11-21",0.01165,{"date":165,"score":62,"percentile":166},"2025-11-22",0.01163,{"date":168,"score":62,"percentile":169},"2025-11-23",0.01153,{"date":171,"score":62,"percentile":172},"2025-11-24",0.01148,{"date":174,"score":62,"percentile":175},"2025-11-25",0.0114,{"date":177,"score":62,"percentile":178},"2025-11-26",0.01075,{"date":180,"score":62,"percentile":181},"2025-11-27",0.01073,{"date":183,"score":62,"percentile":184},"2025-11-28",0.01078,{"date":186,"score":62,"percentile":187},"2025-11-29",0.01112,{"date":189,"score":62,"percentile":190},"2025-11-30",0.01119,{"date":192,"score":62,"percentile":193},"2025-12-01",0.01156,{"date":195,"score":62,"percentile":196},"2025-12-02",0.0115,{"date":198,"score":62,"percentile":199},"2025-12-03",0.01155,{"date":201,"score":62,"percentile":202},"2025-12-04",0.01123,{"date":204,"score":62,"percentile":205},"2025-12-05",0.01135,{"date":207,"score":62,"percentile":208},"2025-12-06",0.01136,{"date":210,"score":62,"percentile":205},"2025-12-07",{"date":212,"score":62,"percentile":213},"2025-12-08",0.01139,{"date":215,"score":62,"percentile":216},"2025-12-09",0.01152,{"date":218,"score":62,"percentile":166},"2025-12-10",{"date":220,"score":62,"percentile":199},"2025-12-11",{"date":222,"score":62,"percentile":169},"2025-12-12",{"date":224,"score":62,"percentile":225},"2025-12-13",0.01142,{"date":227,"score":62,"percentile":228},"2025-12-14",0.01138,{"date":230,"score":62,"percentile":231},"2025-12-15",0.01134,{"date":233,"score":62,"percentile":228},"2025-12-16",{"date":235,"score":62,"percentile":213},"2025-12-17",{"date":237,"score":62,"percentile":238},"2025-12-18",0.01133,{"date":240,"score":62,"percentile":241},"2025-12-19",0.01137,{"date":243,"score":62,"percentile":208},"2025-12-20",{"date":245,"score":62,"percentile":246},"2025-12-21",0.01145,{"date":248,"score":62,"percentile":249},"2025-12-22",0.01147,{"date":251,"score":62,"percentile":252},"2025-12-23",0.01146,{"date":254,"score":62,"percentile":255},"2025-12-24",0.01149,{"date":257,"score":62,"percentile":216},"2025-12-25",{"date":259,"score":62,"percentile":199},"2025-12-26",{"date":261,"score":62,"percentile":199},"2025-12-27",{"date":263,"score":62,"percentile":264},"2025-12-28",0.01151,{"date":266,"score":62,"percentile":267},"2025-12-29",0.01143,{"date":269,"score":62,"percentile":213},"2025-12-30",{"date":271,"score":62,"percentile":213},"2025-12-31",{"date":273,"score":62,"percentile":274},"2026-01-01",0.0117,{"date":276,"score":62,"percentile":163},"2026-01-02",{"date":278,"score":62,"percentile":279},"2026-01-03",0.01169,{"date":281,"score":62,"percentile":282},"2026-01-04",0.0113,{"date":284,"score":62,"percentile":241},"2026-01-05",{"date":286,"score":62,"percentile":238},"2026-01-06",{"date":288,"score":62,"percentile":238},"2026-01-07",{"date":290,"score":62,"percentile":291},"2026-01-08",0.01144,{"date":293,"score":62,"percentile":294},"2026-01-09",0.01162,{"date":296,"score":62,"percentile":279},"2026-01-10",{"date":298,"score":62,"percentile":299},"2026-01-11",0.01166,{"date":301,"score":62,"percentile":302},"2026-01-12",0.01172,{"date":304,"score":62,"percentile":279},"2026-01-13",{"date":306,"score":62,"percentile":299},"2026-01-14",{"date":308,"score":62,"percentile":309},"2026-01-15",0.01181,{"date":311,"score":62,"percentile":312},"2026-01-16",0.01185,{"date":314,"score":62,"percentile":315},"2026-01-17",0.01187,{"date":317,"score":62,"percentile":318},"2026-01-18",0.012,{"date":320,"score":62,"percentile":321},"2026-01-19",0.01196,{"date":323,"score":62,"percentile":324},"2026-01-20",0.01183,{"date":326,"score":62,"percentile":327},"2026-01-21",0.0118,{"date":329,"score":62,"percentile":330},"2026-01-22",0.01182,{"date":332,"score":62,"percentile":321},"2026-01-23",{"date":334,"score":62,"percentile":335},"2026-01-24",0.01197,{"date":337,"score":62,"percentile":335},"2026-01-25",{"date":339,"score":62,"percentile":321},"2026-01-26",{"date":341,"score":62,"percentile":315},"2026-01-27",{"date":343,"score":62,"percentile":312},"2026-01-28",{"date":345,"score":62,"percentile":346},"2026-01-29",0.0119,{"date":348,"score":62,"percentile":349},"2026-01-30",0.01193,{"date":351,"score":62,"percentile":352},"2026-01-31",0.01209,{"date":354,"score":62,"percentile":355},"2026-02-01",0.01239,[357],{"source":66,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":358,"cvss_v4_0":9},{"baseScore":64,"baseSeverity":359,"vectorString":67,"impactScore":360,"exploitabilityScore":361},"MEDIUM",6,4.6,[363,398],{"ecosystem":9,"name":364,"vendor":365,"product":365,"cpe_part":366,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":367},"Linux","linux","a",[368,375,378,381,384,387,390,393,396],{"version":369,"is_range":370,"range_type":72,"version_start":371,"version_start_type":372,"version_end":373,"version_end_type":374,"fixed_in":9},">= 2ccea03a8f7ec93641791f2760d7cdc6cab6205f, \u003C 4325124dde6726267813c736fee61226f1d38f0b",true,"2ccea03a8f7ec93641791f2760d7cdc6cab6205f","including","4325124dde6726267813c736fee61226f1d38f0b","excluding",{"version":376,"is_range":370,"range_type":72,"version_start":371,"version_start_type":372,"version_end":377,"version_end_type":374,"fixed_in":9},">= 2ccea03a8f7ec93641791f2760d7cdc6cab6205f, \u003C e2d3a7009e505e120805f449c832942660f3f7f3","e2d3a7009e505e120805f449c832942660f3f7f3",{"version":379,"is_range":370,"range_type":72,"version_start":371,"version_start_type":372,"version_end":380,"version_end_type":374,"fixed_in":9},">= 2ccea03a8f7ec93641791f2760d7cdc6cab6205f, \u003C 609a7119bffe3ddd7c93f2fa65be8917e02a0b7e","609a7119bffe3ddd7c93f2fa65be8917e02a0b7e",{"version":382,"is_range":370,"range_type":72,"version_start":371,"version_start_type":372,"version_end":383,"version_end_type":374,"fixed_in":9},">= 2ccea03a8f7ec93641791f2760d7cdc6cab6205f, \u003C 2282a6eb6d4e118e294e43dcc421e0e0fe4040b5","2282a6eb6d4e118e294e43dcc421e0e0fe4040b5",{"version":385,"is_range":370,"range_type":72,"version_start":371,"version_start_type":372,"version_end":386,"version_end_type":374,"fixed_in":9},">= 2ccea03a8f7ec93641791f2760d7cdc6cab6205f, \u003C 00bdd9bf1ac6d401ad926d3d8df41b9f1399f646","00bdd9bf1ac6d401ad926d3d8df41b9f1399f646",{"version":388,"is_range":370,"range_type":72,"version_start":371,"version_start_type":372,"version_end":389,"version_end_type":374,"fixed_in":9},">= 2ccea03a8f7ec93641791f2760d7cdc6cab6205f, \u003C 2015c23610cd0efadaeca4d3a8d1dae9a45aa35a","2015c23610cd0efadaeca4d3a8d1dae9a45aa35a",{"version":391,"is_range":370,"range_type":72,"version_start":371,"version_start_type":372,"version_end":392,"version_end_type":374,"fixed_in":9},">= 2ccea03a8f7ec93641791f2760d7cdc6cab6205f, \u003C 27d64436984fb8835a8b7e95993193cc478b162e","27d64436984fb8835a8b7e95993193cc478b162e",{"version":394,"is_range":370,"range_type":72,"version_start":371,"version_start_type":372,"version_end":395,"version_end_type":374,"fixed_in":9},">= 2ccea03a8f7ec93641791f2760d7cdc6cab6205f, \u003C 16b1941eac2bd499f065a6739a40ce0011a3d740","16b1941eac2bd499f065a6739a40ce0011a3d740",{"version":397,"is_range":60,"range_type":72,"version_start":397,"version_start_type":372,"version_end":397,"version_end_type":372,"fixed_in":9},"3.1",{"ecosystem":9,"name":399,"vendor":365,"product":400,"cpe_part":401,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":402},"linux kernel","linux_kernel","o",[403,407,411,415,419,423,427],{"version":404,"is_range":370,"range_type":405,"version_start":397,"version_start_type":372,"version_end":406,"version_end_type":374,"fixed_in":9},"gte3.1_lt4.9.308","cpe","4.9.308",{"version":408,"is_range":370,"range_type":405,"version_start":409,"version_start_type":372,"version_end":410,"version_end_type":374,"fixed_in":9},"gte4.10_lt4.14.273","4.10","4.14.273",{"version":412,"is_range":370,"range_type":405,"version_start":413,"version_start_type":372,"version_end":414,"version_end_type":374,"fixed_in":9},"gte4.15_lt4.19.236","4.15","4.19.236",{"version":416,"is_range":370,"range_type":405,"version_start":417,"version_start_type":372,"version_end":418,"version_end_type":374,"fixed_in":9},"gte4.20_lt5.4.187","4.20","5.4.187",{"version":420,"is_range":370,"range_type":405,"version_start":421,"version_start_type":372,"version_end":422,"version_end_type":374,"fixed_in":9},"gte5.5_lt5.10.108","5.5","5.10.108",{"version":424,"is_range":370,"range_type":405,"version_start":425,"version_start_type":372,"version_end":426,"version_end_type":374,"fixed_in":9},"gte5.11_lt5.15.31","5.11","5.15.31",{"version":428,"is_range":370,"range_type":405,"version_start":429,"version_start_type":372,"version_end":430,"version_end_type":374,"fixed_in":9},"gte5.16_lt5.16.17","5.16","5.16.17"]