Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-28796

Опубликовано: 08 апр. 2022
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.

A use-after-free flaw was found in the Linux kernel’s journaling layer of the ext4 and OCFS2 file system functionality in the way a user can trigger a race condition during writing to the file system. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Отчет

This kind of race condition is hard to trigger and there are no known reproducers to trigger it, so keeping the impact moderate.

Меры по смягчению последствий

To mitigate this issue, prevent the module jbd2 from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. However, if using ext4 or OCFS2 file systems with journaling enabled, then cannot disable this module.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2073941kernel: a use-after-free caused by a transaction_t race condition

EPSS

Процентиль: 29%
0.00104
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
почти 4 года назад

jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.

CVSS3: 7
nvd
почти 4 года назад

jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.

CVSS3: 7
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 7
debian
почти 4 года назад

jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel ...

CVSS3: 7
github
почти 4 года назад

jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.

EPSS

Процентиль: 29%
0.00104
Низкий

7 High

CVSS3