Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-3424

Опубликовано: 06 мар. 2023
Источник: debian
EPSS Низкий

Описание

A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_assignment function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed6.1.4-1package
linuxfixed5.10.178-1bullseyepackage

Примечания

  • https://lore.kernel.org/all/20221006152643.1694235-1-zyytlz.wz@163.com/

  • https://git.kernel.org/linus/643a16a0eb1d6ac23744bb6e90a00fc21148a9dc

  • SGI_GRU not enabled in any Debian kernel

EPSS

Процентиль: 3%
0.0002
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 2 лет назад

A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_assignment function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 7
redhat
почти 3 года назад

A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_assignment function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 7.8
nvd
больше 2 лет назад

A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_assignment function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

suse-cvrf
больше 2 лет назад

Security update for the Linux Kernel (Live Patch 30 for SLE 15 SP1)

suse-cvrf
больше 2 лет назад

Security update for the Linux Kernel (Live Patch 35 for SLE 15 SP1)

EPSS

Процентиль: 3%
0.0002
Низкий