Related Vulnerabilities: CVE-2022-33743  

network backend may cause Linux netfront to use freed SKBs While adding logic to support XDP (eXpress Data Path), a code label was moved in a way allowing for SKBs having references (pointers) retained for further processing to nevertheless be freed.

Description

The MITRE CVE dictionary describes this issue as:

network backend may cause Linux netfront to use freed SKBs While adding logic to support XDP (eXpress Data Path), a code label was moved in a way allowing for SKBs having references (pointers) retained for further processing to nevertheless be freed.

Additional Information

  • Bugzilla 2107924: CVE-2022-33743 kernel: network backend may cause Linux netfront to use freed SKBs (XSA-405)
  • CWE-459: Incomplete Cleanup
  • FAQ: Frequently asked questions about CVE-2022-33743