[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2022-49063":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T02:53:27.892Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":66,"related":67,"reserved_at":9,"published_at":74,"modified_at":75,"state":76,"summary":77,"references_raw":86,"kevs":111,"epss":112,"epss_history":115,"metrics":391,"affected":399},"CVE-2022-49063","In the Linux kernel, the following vulnerability has been resolved:\n\nice: arfs: fix use-after-free when freeing @rx_cpu_rmap\n\nThe CI testing bots triggered the following splat:\n\n[  718.203054] BUG: KASAN: use-after-free in free_irq_cpu_rmap+0x53/0x80\n[  718.206349] Read of size 4 at addr ffff8881bd127e00 by task sh/20834\n[  718.212852] CPU: 28 PID: 20834 Comm: sh Kdump: loaded Tainted: G S      W IOE     5.17.0-rc8_nextqueue-devqueue-02643-g23f3121aca93 #1\n[  718.219695] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0012.070720200218 07/07/2020\n[  718.223418] Call Trace:\n[  718.227139]\n[  718.230783]  dump_stack_lvl+0x33/0x42\n[  718.234431]  print_address_description.constprop.9+0x21/0x170\n[  718.238177]  ? free_irq_cpu_rmap+0x53/0x80\n[  718.241885]  ? free_irq_cpu_rmap+0x53/0x80\n[  718.245539]  kasan_report.cold.18+0x7f/0x11b\n[  718.249197]  ? free_irq_cpu_rmap+0x53/0x80\n[  718.252852]  free_irq_cpu_rmap+0x53/0x80\n[  718.256471]  ice_free_cpu_rx_rmap.part.11+0x37/0x50 [ice]\n[  718.260174]  ice_remove_arfs+0x5f/0x70 [ice]\n[  718.263810]  ice_rebuild_arfs+0x3b/0x70 [ice]\n[  718.267419]  ice_rebuild+0x39c/0xb60 [ice]\n[  718.270974]  ? asm_sysvec_apic_timer_interrupt+0x12/0x20\n[  718.274472]  ? ice_init_phy_user_cfg+0x360/0x360 [ice]\n[  718.278033]  ? delay_tsc+0x4a/0xb0\n[  718.281513]  ? preempt_count_sub+0x14/0xc0\n[  718.284984]  ? delay_tsc+0x8f/0xb0\n[  718.288463]  ice_do_reset+0x92/0xf0 [ice]\n[  718.292014]  ice_pci_err_resume+0x91/0xf0 [ice]\n[  718.295561]  pci_reset_function+0x53/0x80\n\u003C...>\n[  718.393035] Allocated by task 690:\n[  718.433497] Freed by task 20834:\n[  718.495688] Last potentially related work creation:\n[  718.568966] The buggy address belongs to the object at ffff8881bd127e00\n                which belongs to the cache kmalloc-96 of size 96\n[  718.574085] The buggy address is located 0 bytes inside of\n                96-byte region [ffff8881bd127e00, ffff8881bd127e60)\n[  718.579265] The buggy address belongs to the page:\n[  718.598905] Memory state around the buggy address:\n[  718.601809]  ffff8881bd127d00: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n[  718.604796]  ffff8881bd127d80: 00 00 00 00 00 00 00 00 00 00 fc fc fc fc fc fc\n[  718.607794] >ffff8881bd127e00: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n[  718.610811]                    ^\n[  718.613819]  ffff8881bd127e80: 00 00 00 00 00 00 00 00 00 00 00 00 fc fc fc fc\n[  718.617107]  ffff8881bd127f00: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n\nThis is due to that free_irq_cpu_rmap() is always being called\n*after* (devm_)free_irq() and thus it tries to work with IRQ descs\nalready freed. For example, on device reset the driver frees the\nrmap right before allocating a new one (the splat above).\nMake rmap creation and freeing function symmetrical with\n{request,free}_irq() calls i.e. do that on ifup/ifdown instead\nof device probe/remove/resume. These operations can be performed\nindependently from the actual device aRFS configuration.\nAlso, make sure ice_vsi_free_irq() clears IRQ affinity notifiers\nonly when aRFS is disabled -- otherwise, CPU rmap sets and clears\nits own and they must not be touched manually.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-416","Use After Free","The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory \"belongs\" to the code that operates on the new pointer.","weakness","Stable","Variant","High",[],[],[],[],[24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64],{"_key":25},"SUSE-SU-2025:1263-1",{"_key":27},"SUSE-SU-2025:1027-1",{"_key":29},"SUSE-SU-2025:1176-1",{"_key":31},"SUSE-SU-2025:1183-1",{"_key":33},"SUSE-SU-2025:1194-1",{"_key":35},"SUSE-SU-2025:1241-1",{"_key":37},"DLA-4327-1",{"_key":39},"RHSA-2022:6610",{"_key":41},"RHSA-2022:7683",{"_key":43},"DEBIAN-CVE-2022-49063",{"_key":45},"UBUNTU-CVE-2022-49063",{"_key":47},"USN-7654-1",{"_key":49},"USN-7654-2",{"_key":51},"USN-7654-3",{"_key":53},"USN-7654-4",{"_key":55},"USN-7654-5",{"_key":57},"USN-7655-1",{"_key":59},"USN-7686-1",{"_key":61},"USN-7711-1",{"_key":63},"USN-7712-1",{"_key":65},"USN-7712-2",[],[68,69,70,71,72,73],{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},"2025-02-26T01:54:32.460Z","2026-05-11T18:52:18.679Z","Analyzed",{"cisa_kev":78,"cisa_ransomware":78,"cisa_vendor":9,"epss_severity":79,"epss_score":80,"severity":81,"severity_score":82,"severity_version":83,"severity_source":84,"severity_vector":85,"severity_status":76},false,"low",0.00015,"high",7.8,"v3.1","cve.org","CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",[87,93,97,101,105],{"url":88,"sources":89,"tags":91},"https://git.kernel.org/stable/c/ba2f6ec28733fb6b24ed086e676df3df4c138f3f",[84,90],"nvd",[92],"Patch",{"url":94,"sources":95,"tags":96},"https://git.kernel.org/stable/c/618df75f2e30c7838a3e010ca32cd4893ec9fe33",[84,90],[92],{"url":98,"sources":99,"tags":100},"https://git.kernel.org/stable/c/d08d2fb6d99d82da1c63aba5c0d1c6f237e150f3",[84,90],[92],{"url":102,"sources":103,"tags":104},"https://git.kernel.org/stable/c/d7442f512b71fc63a99c8a801422dde4fbbf9f93",[84,90],[92],{"url":106,"sources":107,"tags":108},"https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html",[84,90],[109,110],"Mailing List","Third Party Advisory",[],{"date":113,"score":80,"percentile":114},"2026-06-03",0.03135,[116,120,123,126,129,132,135,138,141,145,148,151,154,157,160,164,167,170,174,178,181,184,187,190,193,196,199,202,205,208,211,214,217,220,223,226,229,233,236,239,242,245,248,251,254,257,260,263,266,269,273,276,279,282,286,289,292,295,298,300,303,306,309,312,315,318,321,323,326,329,332,335,338,341,344,347,349,352,355,358,361,364,367,370,373,376,379,382,385,388],{"date":117,"score":118,"percentile":119},"2025-11-04",0.00038,0.10994,{"date":121,"score":118,"percentile":122},"2025-11-05",0.11018,{"date":124,"score":118,"percentile":125},"2025-11-06",0.11133,{"date":127,"score":118,"percentile":128},"2025-11-07",0.11153,{"date":130,"score":118,"percentile":131},"2025-11-08",0.11164,{"date":133,"score":118,"percentile":134},"2025-11-09",0.11129,{"date":136,"score":118,"percentile":137},"2025-11-10",0.11084,{"date":139,"score":118,"percentile":140},"2025-11-11",0.11095,{"date":142,"score":143,"percentile":144},"2025-11-12",0.00041,0.12053,{"date":146,"score":143,"percentile":147},"2025-11-13",0.1207,{"date":149,"score":143,"percentile":150},"2025-11-14",0.12084,{"date":152,"score":143,"percentile":153},"2025-11-15",0.12083,{"date":155,"score":143,"percentile":156},"2025-11-16",0.12075,{"date":158,"score":143,"percentile":159},"2025-11-17",0.1205,{"date":161,"score":162,"percentile":163},"2025-11-18",0.00057,0.13344,{"date":165,"score":162,"percentile":166},"2025-11-19",0.13362,{"date":168,"score":162,"percentile":169},"2025-11-20",0.13378,{"date":171,"score":172,"percentile":173},"2025-11-21",0.0003,0.07909,{"date":175,"score":176,"percentile":177},"2025-11-22",0.00033,0.09046,{"date":179,"score":176,"percentile":180},"2025-11-23",0.09021,{"date":182,"score":176,"percentile":183},"2025-11-24",0.09011,{"date":185,"score":176,"percentile":186},"2025-11-25",0.09007,{"date":188,"score":176,"percentile":189},"2025-11-26",0.09013,{"date":191,"score":176,"percentile":192},"2025-11-27",0.0902,{"date":194,"score":176,"percentile":195},"2025-11-28",0.08996,{"date":197,"score":176,"percentile":198},"2025-11-29",0.0903,{"date":200,"score":176,"percentile":201},"2025-11-30",0.09039,{"date":203,"score":176,"percentile":204},"2025-12-01",0.09084,{"date":206,"score":176,"percentile":207},"2025-12-02",0.09099,{"date":209,"score":176,"percentile":210},"2025-12-03",0.09128,{"date":212,"score":176,"percentile":213},"2025-12-04",0.09123,{"date":215,"score":176,"percentile":216},"2025-12-05",0.09178,{"date":218,"score":176,"percentile":219},"2025-12-06",0.09193,{"date":221,"score":176,"percentile":222},"2025-12-07",0.092,{"date":224,"score":176,"percentile":225},"2025-12-08",0.09204,{"date":227,"score":176,"percentile":228},"2025-12-09",0.09263,{"date":230,"score":231,"percentile":232},"2025-12-10",0.00037,0.10671,{"date":234,"score":231,"percentile":235},"2025-12-11",0.107,{"date":237,"score":231,"percentile":238},"2025-12-12",0.10721,{"date":240,"score":231,"percentile":241},"2025-12-13",0.10767,{"date":243,"score":231,"percentile":244},"2025-12-14",0.10762,{"date":246,"score":231,"percentile":247},"2025-12-15",0.10704,{"date":249,"score":231,"percentile":250},"2025-12-16",0.1069,{"date":252,"score":231,"percentile":253},"2025-12-17",0.10769,{"date":255,"score":231,"percentile":256},"2025-12-18",0.10819,{"date":258,"score":231,"percentile":259},"2025-12-19",0.10834,{"date":261,"score":231,"percentile":262},"2025-12-20",0.10831,{"date":264,"score":231,"percentile":265},"2025-12-21",0.10813,{"date":267,"score":231,"percentile":268},"2025-12-22",0.10789,{"date":270,"score":271,"percentile":272},"2025-12-23",0.00039,0.11645,{"date":274,"score":271,"percentile":275},"2025-12-24",0.11658,{"date":277,"score":271,"percentile":278},"2025-12-25",0.1173,{"date":280,"score":271,"percentile":281},"2025-12-26",0.11713,{"date":283,"score":284,"percentile":285},"2025-12-27",0.00035,0.10136,{"date":287,"score":271,"percentile":288},"2025-12-28",0.11706,{"date":290,"score":271,"percentile":291},"2025-12-29",0.11655,{"date":293,"score":271,"percentile":294},"2025-12-30",0.11626,{"date":296,"score":271,"percentile":297},"2025-12-31",0.11668,{"date":299,"score":271,"percentile":288},"2026-01-01",{"date":301,"score":271,"percentile":302},"2026-01-02",0.11693,{"date":304,"score":271,"percentile":305},"2026-01-03",0.11654,{"date":307,"score":271,"percentile":308},"2026-01-04",0.11586,{"date":310,"score":271,"percentile":311},"2026-01-05",0.11548,{"date":313,"score":271,"percentile":314},"2026-01-06",0.11558,{"date":316,"score":271,"percentile":317},"2026-01-07",0.11595,{"date":319,"score":271,"percentile":320},"2026-01-08",0.11642,{"date":322,"score":271,"percentile":297},"2026-01-09",{"date":324,"score":271,"percentile":325},"2026-01-10",0.11677,{"date":327,"score":271,"percentile":328},"2026-01-11",0.11649,{"date":330,"score":271,"percentile":331},"2026-01-12",0.11622,{"date":333,"score":271,"percentile":334},"2026-01-13",0.11599,{"date":336,"score":271,"percentile":337},"2026-01-14",0.11653,{"date":339,"score":271,"percentile":340},"2026-01-15",0.11657,{"date":342,"score":271,"percentile":343},"2026-01-16",0.117,{"date":345,"score":271,"percentile":346},"2026-01-17",0.11708,{"date":348,"score":271,"percentile":275},"2026-01-18",{"date":350,"score":271,"percentile":351},"2026-01-19",0.11591,{"date":353,"score":271,"percentile":354},"2026-01-20",0.11571,{"date":356,"score":271,"percentile":357},"2026-01-21",0.11551,{"date":359,"score":271,"percentile":360},"2026-01-22",0.11537,{"date":362,"score":271,"percentile":363},"2026-01-23",0.11625,{"date":365,"score":271,"percentile":366},"2026-01-24",0.11679,{"date":368,"score":271,"percentile":369},"2026-01-25",0.11634,{"date":371,"score":271,"percentile":372},"2026-01-26",0.11574,{"date":374,"score":271,"percentile":375},"2026-01-27",0.11563,{"date":377,"score":271,"percentile":378},"2026-01-28",0.11549,{"date":380,"score":271,"percentile":381},"2026-01-29",0.11523,{"date":383,"score":271,"percentile":384},"2026-01-30",0.11552,{"date":386,"score":271,"percentile":387},"2026-01-31",0.1157,{"date":389,"score":271,"percentile":390},"2026-02-01",0.11576,[392,397],{"source":84,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":393,"cvss_v4_0":9},{"baseScore":82,"baseSeverity":394,"vectorString":85,"impactScore":395,"exploitabilityScore":396},"HIGH",9.8,4.6,{"source":90,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":398,"cvss_v4_0":9},{"baseScore":82,"baseSeverity":394,"vectorString":85,"impactScore":395,"exploitabilityScore":396},[400,409,432],{"ecosystem":9,"name":401,"vendor":402,"product":403,"cpe_part":404,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":405},"debian linux","debian","debian_linux","o",[406],{"version":407,"is_range":78,"range_type":408,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0","cpe",{"ecosystem":9,"name":410,"vendor":411,"product":411,"cpe_part":412,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":413},"Linux","linux","a",[414,421,424,427,430],{"version":415,"is_range":416,"range_type":84,"version_start":417,"version_start_type":418,"version_end":419,"version_end_type":420,"fixed_in":9},">= 28bf26724fdb0e02267d19e280d6717ee810a10d, \u003C ba2f6ec28733fb6b24ed086e676df3df4c138f3f",true,"28bf26724fdb0e02267d19e280d6717ee810a10d","including","ba2f6ec28733fb6b24ed086e676df3df4c138f3f","excluding",{"version":422,"is_range":416,"range_type":84,"version_start":417,"version_start_type":418,"version_end":423,"version_end_type":420,"fixed_in":9},">= 28bf26724fdb0e02267d19e280d6717ee810a10d, \u003C 618df75f2e30c7838a3e010ca32cd4893ec9fe33","618df75f2e30c7838a3e010ca32cd4893ec9fe33",{"version":425,"is_range":416,"range_type":84,"version_start":417,"version_start_type":418,"version_end":426,"version_end_type":420,"fixed_in":9},">= 28bf26724fdb0e02267d19e280d6717ee810a10d, \u003C d08d2fb6d99d82da1c63aba5c0d1c6f237e150f3","d08d2fb6d99d82da1c63aba5c0d1c6f237e150f3",{"version":428,"is_range":416,"range_type":84,"version_start":417,"version_start_type":418,"version_end":429,"version_end_type":420,"fixed_in":9},">= 28bf26724fdb0e02267d19e280d6717ee810a10d, \u003C d7442f512b71fc63a99c8a801422dde4fbbf9f93","d7442f512b71fc63a99c8a801422dde4fbbf9f93",{"version":431,"is_range":78,"range_type":84,"version_start":431,"version_start_type":418,"version_end":431,"version_end_type":418,"fixed_in":9},"5.8",{"ecosystem":9,"name":433,"vendor":411,"product":434,"cpe_part":404,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":435},"linux kernel","linux_kernel",[436,439,443,447,449],{"version":437,"is_range":416,"range_type":408,"version_start":431,"version_start_type":418,"version_end":438,"version_end_type":420,"fixed_in":9},"gte5.8_lt5.10.238","5.10.238",{"version":440,"is_range":416,"range_type":408,"version_start":441,"version_start_type":418,"version_end":442,"version_end_type":420,"fixed_in":9},"gte5.11_lt5.15.184","5.11","5.15.184",{"version":444,"is_range":416,"range_type":408,"version_start":445,"version_start_type":418,"version_end":446,"version_end_type":420,"fixed_in":9},"gte5.16_lt5.17.4","5.16","5.17.4",{"version":448,"is_range":78,"range_type":408,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"5.18:rc1",{"version":450,"is_range":78,"range_type":408,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"5.18:rc2"]