Tracker / CVE-2022-4696
CVE-2022-4696
Alta 7.8
There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter is not increased. This assumption is not always true as calling io_splice on specific files will call the get_uts function which will use current->nsproxy leading to invalidly decreasing its reference counter later causing the use-after-free vulnerability. We recommend upgrading to version 5.10.160 or above
Prodotti e versioni affette
| linux | linux_kernel · 5.11 → 5.12 |
|---|---|
| linux | linux_kernel · 5.4 → 5.10.160 |
| netapp | h300s_firmware |
| netapp | h410c_firmware |
| netapp | h410s_firmware |
| netapp | h500s_firmware |
| netapp | h700s_firmware |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.