Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-40307

Опубликовано: 07 сент. 2022
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.

A race condition in the Linux kernel's EFI capsule loader driver was found in the way it handled write and flush operations on the device node of the EFI capsule. A local user could potentially use this flaw to crash the system.

Отчет

Red Hat Enterprise Linux is not affected by this flaw as the EFI capsule loader is not enabled in any current shipping kernels.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2127424kernel: use-after-free in efi_capsule_write in capsule-loader.c

EPSS

Процентиль: 4%
0.00022
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 3 лет назад

An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.

CVSS3: 4.7
nvd
около 3 лет назад

An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.

CVSS3: 4.7
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 4.7
debian
около 3 лет назад

An issue was discovered in the Linux kernel through 5.19.8. drivers/fi ...

CVSS3: 4.7
github
около 3 лет назад

An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.

EPSS

Процентиль: 4%
0.00022
Низкий

4.7 Medium

CVSS3

Уязвимость CVE-2022-40307