kernel: tun: avoid double free in tun_free_netdev
Published Mar 30, 2023
7.8
HIGHCVSS 3.1
EPSS 0.46%
Description
A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version Linux kernel 5.16-rc7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
- ≥ 5.5 · < 5.10.136
- ≥ 5.11 · < 5.15.12
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.5.1.el8_9
Fixed · RHSA-2023:7077
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9
Fixed · RHSA-2023:6901
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.51.1.el8_8
Fixed · RHSA-2024:1404
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.22.2.el9_1
Fixed · RHSA-2023:1470
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.22.2.el9_1
Fixed · RHSA-2023:1470
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-162.22.2.rt21.186.el9_1
Fixed · RHSA-2023:1469
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2023:1471
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.50.2.el9_0
Fixed · RHSA-2023:1468
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.50.2.rt21.122.el9_0
Fixed · RHSA-2023:1467
Red Hat Enterprise Linux 9.0 Extended Update Support
kpatch-patch
Fixed · RHSA-2023:1466
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Virtualization 4
redhat-virtualization-host
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | Fixed | RHSA-2023:7077 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9 | Fixed | RHSA-2023:6901 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.51.1.el8_8 | Fixed | RHSA-2024:1404 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.22.2.el9_1 | Fixed | RHSA-2023:1470 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.22.2.el9_1 | Fixed | RHSA-2023:1470 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-162.22.2.rt21.186.el9_1 | Fixed | RHSA-2023:1469 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2023:1471 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.50.2.el9_0 | Fixed | RHSA-2023:1468 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.50.2.rt21.122.el9_0 | Fixed | RHSA-2023:1467 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kpatch-patch | Fixed | RHSA-2023:1466 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Keeping Red Hat Enterprise Linux version 8 with Moderate severity, because required patch 158b515f703e (see reference) missed. However, currently Red Hat Enterprise Linux version 8 not affected, because previous patch not backported too: 766b0515d5be ("net: make sure devices go through netdev_wait_all_refs"). Means that it is not possible to trigger the issue for the Red Hat Enterprise Linux 8, but potentially Red Hat Enterprise Linux version 8 could be vulnerable in future, so still need to fix. For the Red Hat Enterprise Linux version 9 there is known way to reproduce the issue.
Red Hat mitigation
To mitigate this issue, prevent the tun module from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 14, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2023-2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.46% (0.00459) | 37.59th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.46% (0.00456) | 35.93th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.07% (0.00072) | 19.37th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 31, 2023 | 0.04% (0.00042) | 5.67th | v3 (v2023.03.01) |
References (8)
- http://packetstormsecurity.com/files/171912/CentOS-Stream-9-Missing-Kernel-Security-Fix.html Third Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2022-4744 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2156322 Issue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=158b515f703e Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-4744
- https://security.netapp.com/advisory/ntap-20230526-0009/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-4744
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/171912/CentOS-Stream-9-Missing-Kernel-Security-Fix.html | Third Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2022-4744 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2156322 | Issue Tracking | |
| https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=158b515f703e | Vendor Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-4744 | ||
| https://security.netapp.com/advisory/ntap-20230526-0009/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-4744 |
Change history (0)
No recorded changes yet.