[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2022-49667":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T20:55:29.923Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":42,"related":43,"reserved_at":9,"published_at":49,"modified_at":50,"state":51,"summary":52,"references_raw":61,"kevs":96,"epss":97,"epss_history":100,"metrics":369,"affected":377},"CVE-2022-49667","In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bonding: fix use-after-free after 802.3ad slave unbind\n\ncommit 0622cab0341c (\"bonding: fix 802.3ad aggregator reselection\"),\nresolve case, when there is several aggregation groups in the same bond.\nbond_3ad_unbind_slave will invalidate (clear) aggregator when\n__agg_active_ports return zero. So, ad_clear_agg can be executed even, when\nnum_of_ports!=0. Than bond_3ad_unbind_slave can be executed again for,\npreviously cleared aggregator. NOTE: at this time bond_3ad_unbind_slave\nwill not update slave ports list, because lag_ports==NULL. So, here we\ngot slave ports, pointing to freed aggregator memory.\n\nFix with checking actual number of ports in group (as was before\ncommit 0622cab0341c (\"bonding: fix 802.3ad aggregator reselection\") ),\nbefore ad_clear_agg().\n\nThe KASAN logs are as follows:\n\n[  767.617392] ==================================================================\n[  767.630776] BUG: KASAN: use-after-free in bond_3ad_state_machine_handler+0x13dc/0x1470\n[  767.638764] Read of size 2 at addr ffff00011ba9d430 by task kworker/u8:7/767\n[  767.647361] CPU: 3 PID: 767 Comm: kworker/u8:7 Tainted: G           O 5.15.11 #15\n[  767.655329] Hardware name: DNI AmazonGo1 A7040 board (DT)\n[  767.660760] Workqueue: lacp_1 bond_3ad_state_machine_handler\n[  767.666468] Call trace:\n[  767.668930]  dump_backtrace+0x0/0x2d0\n[  767.672625]  show_stack+0x24/0x30\n[  767.675965]  dump_stack_lvl+0x68/0x84\n[  767.679659]  print_address_description.constprop.0+0x74/0x2b8\n[  767.685451]  kasan_report+0x1f0/0x260\n[  767.689148]  __asan_load2+0x94/0xd0\n[  767.692667]  bond_3ad_state_machine_handler+0x13dc/0x1470",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-416","Use After Free","The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory \"belongs\" to the code that operates on the new pointer.","weakness","Stable","Variant","High",[],[],[],[],[24,26,28,30,32,34,36,38,40],{"_key":25},"SUSE-SU-2025:1027-1",{"_key":27},"SUSE-SU-2025:1176-1",{"_key":29},"SUSE-SU-2025:1183-1",{"_key":31},"SUSE-SU-2025:1241-1",{"_key":33},"SUSE-SU-2025:1293-1",{"_key":35},"RHSA-2026:1494",{"_key":37},"RHSA-2026:1495",{"_key":39},"DEBIAN-CVE-2022-49667",{"_key":41},"UBUNTU-CVE-2022-49667",[],[44,45,46,47,48],{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},"2025-02-26T02:24:01.818Z","2026-05-11T19:04:21.836Z","Analyzed",{"cisa_kev":53,"cisa_ransomware":53,"cisa_vendor":9,"epss_severity":54,"epss_score":55,"severity":56,"severity_score":57,"severity_version":58,"severity_source":59,"severity_vector":60,"severity_status":51},false,"low",0.00017,"high",7.8,"v3.1","cve.org","CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",[62,68,72,76,80,84,88,92],{"url":63,"sources":64,"tags":66},"https://git.kernel.org/stable/c/a853b7a3a9fd1d74a4ccdd9cd73512b7dace2f1e",[59,65],"nvd",[67],"Patch",{"url":69,"sources":70,"tags":71},"https://git.kernel.org/stable/c/b90ac60303063a43e17dd4aec159067599d255e6",[59,65],[67],{"url":73,"sources":74,"tags":75},"https://git.kernel.org/stable/c/f162f7c348fa2a5555bafdb5cc890b89b221e69c",[59,65],[67],{"url":77,"sources":78,"tags":79},"https://git.kernel.org/stable/c/893825289ba840afd86bfffcb6f7f363c73efff8",[59,65],[67],{"url":81,"sources":82,"tags":83},"https://git.kernel.org/stable/c/63b2fe509f69b90168a75e04e14573dccf7984e6",[59,65],[67],{"url":85,"sources":86,"tags":87},"https://git.kernel.org/stable/c/ef0af7d08d26c5333ff4944a559279464edf6f15",[59,65],[67],{"url":89,"sources":90,"tags":91},"https://git.kernel.org/stable/c/2765749def4765c5052a4c66445cf4c96fcccdbc",[59,65],[67],{"url":93,"sources":94,"tags":95},"https://git.kernel.org/stable/c/050133e1aa2cb49bb17be847d48a4431598ef562",[59,65],[67],[],{"date":98,"score":55,"percentile":99},"2026-06-04",0.04187,[101,105,108,111,114,117,120,123,126,130,133,136,139,142,145,149,152,155,158,162,165,168,171,174,177,180,183,186,189,192,195,198,201,204,207,210,213,216,219,222,225,228,231,234,237,240,243,246,248,251,255,257,260,263,266,269,272,275,277,280,283,286,289,292,295,298,301,304,307,309,312,315,318,321,323,326,329,332,335,338,341,343,346,348,351,353,356,360,363,366],{"date":102,"score":103,"percentile":104},"2025-11-04",0.00029,0.06911,{"date":106,"score":103,"percentile":107},"2025-11-05",0.06932,{"date":109,"score":103,"percentile":110},"2025-11-06",0.07049,{"date":112,"score":103,"percentile":113},"2025-11-07",0.07073,{"date":115,"score":103,"percentile":116},"2025-11-08",0.07067,{"date":118,"score":103,"percentile":119},"2025-11-09",0.07045,{"date":121,"score":103,"percentile":122},"2025-11-10",0.07019,{"date":124,"score":103,"percentile":125},"2025-11-11",0.07046,{"date":127,"score":128,"percentile":129},"2025-11-12",0.00031,0.0778,{"date":131,"score":128,"percentile":132},"2025-11-13",0.07817,{"date":134,"score":128,"percentile":135},"2025-11-14",0.07864,{"date":137,"score":128,"percentile":138},"2025-11-15",0.07919,{"date":140,"score":128,"percentile":141},"2025-11-16",0.07933,{"date":143,"score":128,"percentile":144},"2025-11-17",0.07923,{"date":146,"score":147,"percentile":148},"2025-11-18",0.00057,0.13434,{"date":150,"score":147,"percentile":151},"2025-11-19",0.13451,{"date":153,"score":147,"percentile":154},"2025-11-20",0.13466,{"date":156,"score":128,"percentile":157},"2025-11-21",0.08078,{"date":159,"score":160,"percentile":161},"2025-11-22",0.00034,0.09282,{"date":163,"score":160,"percentile":164},"2025-11-23",0.09253,{"date":166,"score":160,"percentile":167},"2025-11-24",0.09237,{"date":169,"score":160,"percentile":170},"2025-11-25",0.09226,{"date":172,"score":160,"percentile":173},"2025-11-26",0.09233,{"date":175,"score":160,"percentile":176},"2025-11-27",0.09245,{"date":178,"score":160,"percentile":179},"2025-11-28",0.09227,{"date":181,"score":160,"percentile":182},"2025-11-29",0.09252,{"date":184,"score":160,"percentile":185},"2025-11-30",0.0926,{"date":187,"score":160,"percentile":188},"2025-12-01",0.09304,{"date":190,"score":160,"percentile":191},"2025-12-02",0.09317,{"date":193,"score":160,"percentile":194},"2025-12-03",0.09341,{"date":196,"score":160,"percentile":197},"2025-12-04",0.09338,{"date":199,"score":160,"percentile":200},"2025-12-05",0.09395,{"date":202,"score":160,"percentile":203},"2025-12-06",0.09406,{"date":205,"score":160,"percentile":206},"2025-12-07",0.0941,{"date":208,"score":160,"percentile":209},"2025-12-08",0.09416,{"date":211,"score":160,"percentile":212},"2025-12-09",0.09474,{"date":214,"score":160,"percentile":215},"2025-12-10",0.09555,{"date":217,"score":160,"percentile":218},"2025-12-11",0.09588,{"date":220,"score":160,"percentile":221},"2025-12-12",0.0961,{"date":223,"score":160,"percentile":224},"2025-12-13",0.09637,{"date":226,"score":160,"percentile":227},"2025-12-14",0.09631,{"date":229,"score":160,"percentile":230},"2025-12-15",0.09557,{"date":232,"score":160,"percentile":233},"2025-12-16",0.09545,{"date":235,"score":160,"percentile":236},"2025-12-17",0.09627,{"date":238,"score":160,"percentile":239},"2025-12-18",0.09685,{"date":241,"score":160,"percentile":242},"2025-12-19",0.09706,{"date":244,"score":160,"percentile":245},"2025-12-20",0.097,{"date":247,"score":160,"percentile":239},"2025-12-21",{"date":249,"score":160,"percentile":250},"2025-12-22",0.09658,{"date":252,"score":253,"percentile":254},"2025-12-23",0.00036,0.10288,{"date":256,"score":253,"percentile":254},"2025-12-24",{"date":258,"score":253,"percentile":259},"2025-12-25",0.10372,{"date":261,"score":253,"percentile":262},"2025-12-26",0.10367,{"date":264,"score":253,"percentile":265},"2025-12-27",0.10364,{"date":267,"score":253,"percentile":268},"2025-12-28",0.1037,{"date":270,"score":253,"percentile":271},"2025-12-29",0.10334,{"date":273,"score":253,"percentile":274},"2025-12-30",0.10314,{"date":276,"score":253,"percentile":265},"2025-12-31",{"date":278,"score":253,"percentile":279},"2026-01-01",0.10411,{"date":281,"score":253,"percentile":282},"2026-01-02",0.10409,{"date":284,"score":253,"percentile":285},"2026-01-03",0.10382,{"date":287,"score":253,"percentile":288},"2026-01-04",0.10301,{"date":290,"score":253,"percentile":291},"2026-01-05",0.10262,{"date":293,"score":253,"percentile":294},"2026-01-06",0.10251,{"date":296,"score":253,"percentile":297},"2026-01-07",0.10283,{"date":299,"score":253,"percentile":300},"2026-01-08",0.10336,{"date":302,"score":253,"percentile":303},"2026-01-09",0.10366,{"date":305,"score":253,"percentile":306},"2026-01-10",0.10389,{"date":308,"score":253,"percentile":259},"2026-01-11",{"date":310,"score":253,"percentile":311},"2026-01-12",0.10347,{"date":313,"score":253,"percentile":314},"2026-01-13",0.1031,{"date":316,"score":253,"percentile":317},"2026-01-14",0.10361,{"date":319,"score":253,"percentile":320},"2026-01-15",0.10374,{"date":322,"score":253,"percentile":282},"2026-01-16",{"date":324,"score":253,"percentile":325},"2026-01-17",0.10425,{"date":327,"score":253,"percentile":328},"2026-01-18",0.10386,{"date":330,"score":253,"percentile":331},"2026-01-19",0.10339,{"date":333,"score":253,"percentile":334},"2026-01-20",0.10312,{"date":336,"score":253,"percentile":337},"2026-01-21",0.10276,{"date":339,"score":253,"percentile":340},"2026-01-22",0.10269,{"date":342,"score":253,"percentile":265},"2026-01-23",{"date":344,"score":253,"percentile":345},"2026-01-24",0.10416,{"date":347,"score":253,"percentile":320},"2026-01-25",{"date":349,"score":253,"percentile":350},"2026-01-26",0.10328,{"date":352,"score":253,"percentile":334},"2026-01-27",{"date":354,"score":253,"percentile":355},"2026-01-28",0.10287,{"date":357,"score":358,"percentile":359},"2026-01-29",0.00037,0.10916,{"date":361,"score":358,"percentile":362},"2026-01-30",0.10936,{"date":364,"score":358,"percentile":365},"2026-01-31",0.10952,{"date":367,"score":253,"percentile":368},"2026-02-01",0.10303,[370,375],{"source":59,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":371,"cvss_v4_0":9},{"baseScore":57,"baseSeverity":372,"vectorString":60,"impactScore":373,"exploitabilityScore":374},"HIGH",9.8,4.6,{"source":65,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":376,"cvss_v4_0":9},{"baseScore":57,"baseSeverity":372,"vectorString":60,"impactScore":373,"exploitabilityScore":374},[378,413],{"ecosystem":9,"name":379,"vendor":380,"product":380,"cpe_part":381,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":382},"Linux","linux","a",[383,390,393,396,399,402,405,408,411],{"version":384,"is_range":385,"range_type":59,"version_start":386,"version_start_type":387,"version_end":388,"version_end_type":389,"fixed_in":9},">= 0622cab0341cac6b30da177b0faa39fae0680e71, \u003C a853b7a3a9fd1d74a4ccdd9cd73512b7dace2f1e",true,"0622cab0341cac6b30da177b0faa39fae0680e71","including","a853b7a3a9fd1d74a4ccdd9cd73512b7dace2f1e","excluding",{"version":391,"is_range":385,"range_type":59,"version_start":386,"version_start_type":387,"version_end":392,"version_end_type":389,"fixed_in":9},">= 0622cab0341cac6b30da177b0faa39fae0680e71, \u003C b90ac60303063a43e17dd4aec159067599d255e6","b90ac60303063a43e17dd4aec159067599d255e6",{"version":394,"is_range":385,"range_type":59,"version_start":386,"version_start_type":387,"version_end":395,"version_end_type":389,"fixed_in":9},">= 0622cab0341cac6b30da177b0faa39fae0680e71, \u003C f162f7c348fa2a5555bafdb5cc890b89b221e69c","f162f7c348fa2a5555bafdb5cc890b89b221e69c",{"version":397,"is_range":385,"range_type":59,"version_start":386,"version_start_type":387,"version_end":398,"version_end_type":389,"fixed_in":9},">= 0622cab0341cac6b30da177b0faa39fae0680e71, \u003C 893825289ba840afd86bfffcb6f7f363c73efff8","893825289ba840afd86bfffcb6f7f363c73efff8",{"version":400,"is_range":385,"range_type":59,"version_start":386,"version_start_type":387,"version_end":401,"version_end_type":389,"fixed_in":9},">= 0622cab0341cac6b30da177b0faa39fae0680e71, \u003C 63b2fe509f69b90168a75e04e14573dccf7984e6","63b2fe509f69b90168a75e04e14573dccf7984e6",{"version":403,"is_range":385,"range_type":59,"version_start":386,"version_start_type":387,"version_end":404,"version_end_type":389,"fixed_in":9},">= 0622cab0341cac6b30da177b0faa39fae0680e71, \u003C ef0af7d08d26c5333ff4944a559279464edf6f15","ef0af7d08d26c5333ff4944a559279464edf6f15",{"version":406,"is_range":385,"range_type":59,"version_start":386,"version_start_type":387,"version_end":407,"version_end_type":389,"fixed_in":9},">= 0622cab0341cac6b30da177b0faa39fae0680e71, \u003C 2765749def4765c5052a4c66445cf4c96fcccdbc","2765749def4765c5052a4c66445cf4c96fcccdbc",{"version":409,"is_range":385,"range_type":59,"version_start":386,"version_start_type":387,"version_end":410,"version_end_type":389,"fixed_in":9},">= 0622cab0341cac6b30da177b0faa39fae0680e71, \u003C 050133e1aa2cb49bb17be847d48a4431598ef562","050133e1aa2cb49bb17be847d48a4431598ef562",{"version":412,"is_range":53,"range_type":59,"version_start":412,"version_start_type":387,"version_end":412,"version_end_type":387,"fixed_in":9},"4.7",{"ecosystem":9,"name":414,"vendor":380,"product":415,"cpe_part":416,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":417},"linux kernel","linux_kernel","o",[418,422,426,430,434,438,442,446,448,450,452],{"version":419,"is_range":385,"range_type":420,"version_start":412,"version_start_type":387,"version_end":421,"version_end_type":389,"fixed_in":9},"gte4.7_lt4.9.322","cpe","4.9.322",{"version":423,"is_range":385,"range_type":420,"version_start":424,"version_start_type":387,"version_end":425,"version_end_type":389,"fixed_in":9},"gte4.10_lt4.14.287","4.10","4.14.287",{"version":427,"is_range":385,"range_type":420,"version_start":428,"version_start_type":387,"version_end":429,"version_end_type":389,"fixed_in":9},"gte4.15_lt4.19.251","4.15","4.19.251",{"version":431,"is_range":385,"range_type":420,"version_start":432,"version_start_type":387,"version_end":433,"version_end_type":389,"fixed_in":9},"gte4.20_lt5.4.204","4.20","5.4.204",{"version":435,"is_range":385,"range_type":420,"version_start":436,"version_start_type":387,"version_end":437,"version_end_type":389,"fixed_in":9},"gte5.5_lt5.10.129","5.5","5.10.129",{"version":439,"is_range":385,"range_type":420,"version_start":440,"version_start_type":387,"version_end":441,"version_end_type":389,"fixed_in":9},"gte5.11_lt5.15.53","5.11","5.15.53",{"version":443,"is_range":385,"range_type":420,"version_start":444,"version_start_type":387,"version_end":445,"version_end_type":389,"fixed_in":9},"gte5.16_lt5.18.10","5.16","5.18.10",{"version":447,"is_range":53,"range_type":420,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"5.19:rc1",{"version":449,"is_range":53,"range_type":420,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"5.19:rc2",{"version":451,"is_range":53,"range_type":420,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"5.19:rc3",{"version":453,"is_range":53,"range_type":420,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"5.19:rc4"]