VYPR
High severity7.1NVD Advisory· Published Jun 20, 2024· Updated Jun 17, 2026

CVE-2022-48757

CVE-2022-48757

Description

In the Linux kernel, the following vulnerability has been resolved:

net: fix information leakage in /proc/net/ptype

In one net namespace, after creating a packet socket without binding it to a device, users in other net namespaces can observe the new packet_type added by this packet socket by reading /proc/net/ptype file. This is minor information leakage as packet socket is namespace aware.

Add a net pointer in packet_type to keep the net namespace of of corresponding packet socket. In ptype_seq_show, this net pointer must be checked when it is not NULL.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Linux/Kernel4 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=2.6.26,<4.4.302
    • cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 2.6.26
  • osv-coords
    Range: >= 2.6.26, < 4.4.302

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.