Answer in brief
CVE-2022-48670 records a Unknown severity vulnerability in peci: cpu: Fix use-after-free in adev_release(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=93e1821c80f9460c8931dc4bc090ede794f966cd <c87f1f99e26ea4ae08cabe753ae98e5626bdba89 || >=93e1821c80f9460c8931dc4bc090ede794f966cd <1c11289b34ab67ed080bbe0f1855c4938362d9cf | c87f1f99e26ea4ae08cabe753ae98e5626bdba89, 1c11289b34ab67ed080bbe0f1855c4938362d9cf |
| Linux/Linuxgeneric | 5.18 | Not reported |
| linux/linux_kernelgeneric | -1da177e4c3f4 | Not reported |
Published upstream
May 3, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 13, 2026
In the Linux kernel, the following vulnerability has been resolved: peci: cpu: Fix use-after-free in adev_release() When auxiliary_device_add() returns an error, auxiliary_device_uninit() is called, which causes refcount for device to be decremented and .release callback will be triggered. Because adev_release() re-calls auxiliary_device_uninit(), it will cause use-after-free: [ 1269.455172] WARNING: CPU: 0 PID: 14267 at lib/refcount.c:28 refcount_warn_saturate+0x110/0x15 [ 1269.464007] refcount_t: underflow; use-after-free.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2022-48670 records a Unknown severity vulnerability in peci: cpu: Fix use-after-free in adev_release(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=93e1821c80f9460c8931dc4bc090ede794f966cd <c87f1f99e26ea4ae08cabe753ae98e5626bdba89 || >=93e1821c80f9460c8931dc4bc090ede794f966cd <1c11289b34ab67ed080bbe0f1855c4938362d9cf | c87f1f99e26ea4ae08cabe753ae98e5626bdba89, 1c11289b34ab67ed080bbe0f1855c4938362d9cf |
| Linux/Linuxgeneric | 5.18 | Not reported |
| linux/linux_kernelgeneric | -1da177e4c3f4 | Not reported |
Published upstream
May 3, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 13, 2026
In the Linux kernel, the following vulnerability has been resolved: peci: cpu: Fix use-after-free in adev_release() When auxiliary_device_add() returns an error, auxiliary_device_uninit() is called, which causes refcount for device to be decremented and .release callback will be triggered. Because adev_release() re-calls auxiliary_device_uninit(), it will cause use-after-free: [ 1269.455172] WARNING: CPU: 0 PID: 14267 at lib/refcount.c:28 refcount_warn_saturate+0x110/0x15 [ 1269.464007] refcount_t: underflow; use-after-free.
Quoted source text, attributed separately from HOL analysis.