Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-45885

Опубликовано: 15 нояб. 2022
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected.

A race condition flaw leading to a use-after-free issue was found in the Linux kernel media subsystem in the DVB core device driver. It could occur in the dvb_frontend() function when closing the device node of dvb_frontend if the device is disconnected. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

Отчет

Because exploitation of this flaw requires that an attacker has either: local privileges on and physical access to the system, or administrative privileges sufficient to virtually attach or detach harware devices, Red Hat assesses that the impact of this vulnerability as Moderate.

Меры по смягчению последствий

To mitigate this issue, it is possible to prevent the affected code from being loaded by blacklisting the dvb-core kernel module. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 8kernelWill not fix
Red Hat Enterprise Linux 8kernel-rtWill not fix
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362->CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2148513kernel: use-after-free due to race condition occurring in dvb_frontend.c

EPSS

Процентиль: 2%
0.00014
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
почти 3 года назад

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected.

CVSS3: 7
nvd
почти 3 года назад

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected.

CVSS3: 7
debian
почти 3 года назад

An issue was discovered in the Linux kernel through 6.0.9. drivers/med ...

CVSS3: 7
github
почти 3 года назад

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected.

CVSS3: 7
fstec
почти 3 года назад

Уязвимость драйвера DVB (drivers/media/dvb-core/dvb_frontend.c) ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании или повысить свои привилегии.

EPSS

Процентиль: 2%
0.00014
Низкий

6.4 Medium

CVSS3