Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-22942

Опубликовано: 13 дек. 2023
Источник: debian
EPSS Средний

Описание

The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed5.15.15-2package
linuxnot-affectedstretchpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2022/01/27/4

  • https://www.openwall.com/lists/oss-security/2022/02/03/1

  • Fixed by: https://git.kernel.org/linus/a0f90c8815706981c483a652a6aefca51a5e191c

  • https://github.com/opensrcsec/same_type_object_reuse_exploits/blob/main/cve-2022-22942-dc.c

  • https://github.com/opensrcsec/same_type_object_reuse_exploits/blob/main/cve-2022-22942.c

EPSS

Процентиль: 94%
0.13103
Средний

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 1 года назад

The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer.

CVSS3: 7
redhat
больше 3 лет назад

The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer.

CVSS3: 7.8
nvd
больше 1 года назад

The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer.

CVSS3: 7.8
github
больше 1 года назад

The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer.

CVSS3: 7
fstec
больше 3 лет назад

Уязвимость функции vmw_execbuf_copy_fence_user() (drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c) модуля vmwgfx ядра операционных систем Linux, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 94%
0.13103
Средний