
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-34494 is a double-free vulnerability discovered in the virtio RPMSG bus driver of the Linux kernel before version 5.18.4. The vulnerability specifically affects the rpmsg_virtio_add_ctrl_dev function in drivers/rpmsg/virtio_rpmsg_bus.c (MITRE CVE, Ubuntu Security).
The vulnerability occurs in the rpmsg_virtio_add_ctrl_dev function where a double-free condition exists in certain error paths. The issue stems from an unnecessary call to kfree() on a pointer that would already be freed in virtio_rpmsg_release_device() when rpmsg_ctrldev_register_device() fails (GitHub Commit). The vulnerability has been assigned a CVSS 3 Severity Score of 5.5 (Medium) (Ubuntu Security).
If exploited, this vulnerability could allow a local attacker to potentially cause a denial of service condition through a system crash (Ubuntu Security).
The vulnerability requires local access to the system to be exploited. There are no known reports of this vulnerability being exploited in the wild (Ubuntu Security).
The vulnerability has been fixed in Linux kernel version 5.18.4. Ubuntu has released patches for affected versions, including Ubuntu 22.04 LTS (jammy) with version 5.15.0-48.54 and other supported releases (Ubuntu Security). Users are advised to update their systems to the patched versions.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."