Back

MEDIUM

kernel: net scheduler use-after-free information disclosure vulnerability

Published Oct 19, 2022

Description

A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local, unprivileged user to crash the system, causing a denial of service.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, prevent module sch_sfb from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. If the sch_sfb module is enabled, then don't install sch_cake as a child qdisc of sch_sfb.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 19, 2022
Updated May 9, 2025
Reserved Oct 18, 2022
CISA Vulnrichment
Updated May 9, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 31, 2022
ENISA EUVD
Assigner redhat
Published Oct 19, 2022
Updated May 9, 2025
Exploited since n/a
EUVD-2022-42950