๐Ÿ” CVE Alert

CVE-2022-49258

HIGH 7.8

crypto: ccree - Fix use after free in cc_cipher_exit()

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: crypto: ccree - Fix use after free in cc_cipher_exit() kfree_sensitive(ctx_p->user.key) will free the ctx_p->user.key. But ctx_p->user.key is still used in the next line, which will lead to a use after free. We can call kfree_sensitive() after dev_dbg() to avoid the uaf.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Feb 26, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
63ee04c8b491ee148489347e7da9fbfd982ca2bb < c93017c8d5ebf55a4e453ac7c84cc84cf92ab570 63ee04c8b491ee148489347e7da9fbfd982ca2bb < 335bf1fc74f775a8255257aa3e33763f2257b676 63ee04c8b491ee148489347e7da9fbfd982ca2bb < 25c358efee5153dfd240d4e0d3169d5bebe9cacd 63ee04c8b491ee148489347e7da9fbfd982ca2bb < cffb5382bd8d3cf21b874ab5b84bf7618932286b 63ee04c8b491ee148489347e7da9fbfd982ca2bb < 3d950c34074ed74d2713c3856ba01264523289e6
Linux / Linux
4.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c93017c8d5ebf55a4e453ac7c84cc84cf92ab570 git.kernel.org: https://git.kernel.org/stable/c/335bf1fc74f775a8255257aa3e33763f2257b676 git.kernel.org: https://git.kernel.org/stable/c/25c358efee5153dfd240d4e0d3169d5bebe9cacd git.kernel.org: https://git.kernel.org/stable/c/cffb5382bd8d3cf21b874ab5b84bf7618932286b git.kernel.org: https://git.kernel.org/stable/c/3d950c34074ed74d2713c3856ba01264523289e6