U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-48740

Change History

New CVE Received by NIST 6/20/2024 8:15:12 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

selinux: fix double free of cond_list on error paths

On error path from cond_read_list() and duplicate_policydb_cond_list()
the cond_list_destroy() gets called a second time in caller functions,
resulting in NULL pointer deref.  Fix this by resetting the
cond_list_len to 0 in cond_list_destroy(), making subsequent calls a
noop.

Also consistently reset the cond_list pointer to NULL after freeing.

[PM: fix line lengths in the description]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/186edf7e368c40d06cf727a1ad14698ea67b74ad [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/70caa32e6d81f45f0702070c0e4dfe945e92fbd7 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/7ed9cbf7ac0d4ed86b356e1b944304ae9ee450d4 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/f446089a268c8fc6908488e991d28a9b936293db [No types assigned]