Tracker / CVE-2022-50022
CVE-2022-50022
Alta 7.8
In the Linux kernel, the following vulnerability has been resolved: drivers:md:fix a potential use-after-free bug In line 2884, "raid5_release_stripe(sh);" drops the reference to sh and may cause sh to be released. However, sh is subsequently used in lines 2886 "if (sh->batch_head && sh != sh->batch_head)". This may result in an use-after-free bug. It can be fixed by moving "raid5_release_stripe(sh);" to the bottom of the function.
Prodotti e versioni affette
| linux | linux_kernel · 4.1 → 4.9.326 |
|---|---|
| linux | linux_kernel · 4.10 → 4.14.291 |
| linux | linux_kernel · 4.15 → 4.19.256 |
| linux | linux_kernel · 4.20 → 5.4.211 |
| linux | linux_kernel · 5.11 → 5.15.63 |
| linux | linux_kernel · 5.16 → 5.19.4 |
| linux | linux_kernel · 5.5 → 5.10.138 |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.