CVE-2022-45886 is a Linux kernel use-after-free flaw in the DVB core networking component, drivers/media/dvb-core/dvb_net.c. A time-of-check/time-of-use race between DVB device disconnection and dvb_device_open() can let a low-privileged local attacker crash a vulnerable system or potentially elevate privileges. Exploitation requires access to DVB hardware—either physical access or an authenticated remote user able to predict the hardware's disconnect/reconnect timing.
The issue affects kernels through version 6.0.9 and was fixed upstream by serializing open, close, release, and removal operations with a remove_mutex; opens during device removal are rejected with -ENODEV. Red Hat rated the flaw Moderate with CVSS 7.0 and issued fixes for affected RHEL 8 kernel variants through November 2023; RHEL 9 and RHEL 9 real-time kernels are not affected. Organizations unable to patch can mitigate exposure by blacklisting the dvb-core kernel module.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:7548 and RHSA-2023:7549 for affected RHEL 8 kernel-rt and kernel packages, respectively, and RHSA-2023:7539 for RHEL 8.8 Extended Update Support. These errata addressed the DVB-core race-condition use-after-free vulnerability.
Red Hat released RHSA-2023:7398 to address CVE-2022-45886 for the RHEL 8.6 Extended Update Support kernel. The advisory also provided a fixed kernel for Red Hat Virtualization 4 on RHEL 8.
Guilherme de Almeida Suckevicz reported the Linux kernel DVB networking use-after-free issue, later designated CVE-2022-45886. The flaw stems from a race between device disconnection and dvb_device_open().
Hyunwoo Kim submitted a patch in a four-patch series to fix use-after-free conditions in the DVB core's dvb_net component. The proposed change added remove_mutex locking and rejected device opens with -ENODEV while removal was in progress.
Fedora addressed CVE-2022-45886 in its stable kernel version 6.3.7.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.