Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2588

Опубликовано: 09 авг. 2022
Источник: redhat
CVSS3: 7.8

Описание

It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.

A use-after-free flaw was found in route4_change in the net/sched/cls_route.c filter implementation in the Linux kernel. This flaw allows a local user to crash the system and possibly lead to a local privilege escalation problem.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelAffected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2022:733802.11.2022
Red Hat Enterprise Linux 7kernelFixedRHSA-2022:733702.11.2022
Red Hat Enterprise Linux 7kpatch-patchFixedRHSA-2022:734402.11.2022
Red Hat Enterprise Linux 7.4 Advanced Update SupportkernelFixedRHSA-2022:714625.10.2022
Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)kernelFixedRHSA-2022:717125.10.2022
Red Hat Enterprise Linux 7.6 Telco Extended Update SupportkernelFixedRHSA-2022:717125.10.2022
Red Hat Enterprise Linux 7.6 Update Services for SAP SolutionskernelFixedRHSA-2022:717125.10.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2114849kernel: a use-after-free in cls_route filter implementation may lead to privilege escalation

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.

CVSS3: 5.3
nvd
больше 1 года назад

It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.

CVSS3: 7.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 5.3
debian
больше 1 года назад

It was discovered that the cls_route filter implementation in the Linu ...

oracle-oval
почти 3 года назад

ELSA-2022-9699: Unbreakable Enterprise kernel-container security update (IMPORTANT)

7.8 High

CVSS3