Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-48668

Опубликовано: 28 апр. 2024
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: smb3: fix temporary data corruption in collapse range collapse range doesn't discard the affected cached region so can risk temporarily corrupting the file data. This fixes xfstest generic/031 I also decided to merge a minor cleanup to this into the same patch (avoiding rereading inode size repeatedly unnecessarily) to make it clearer.

A flaw was found in the Linux kernel's Server Message Block version 3 (SMB3) file-sharing protocol. This flaw occurs during the collapse range operation, where the cached region is not properly discarded. This improper handling can lead to temporary data corruption in files, particularly when multiple file operations occur simultaneously. The issue was identified and resolved by ensuring that the collapse range operation correctly handles cached regions to prevent this data corruption. The vulnerability was fixed in kernel versions such as 5.19.12 and later, along with a minor cleanup that streamlined the handling of inode sizes to make the code more efficient.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-696
https://bugzilla.redhat.com/show_bug.cgi?id=2277790kernel: smb3: fix temporary data corruption in collapse range

EPSS

Процентиль: 3%
0.00016
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: smb3: fix temporary data corruption in collapse range collapse range doesn't discard the affected cached region so can risk temporarily corrupting the file data. This fixes xfstest generic/031 I also decided to merge a minor cleanup to this into the same patch (avoiding rereading inode size repeatedly unnecessarily) to make it clearer.

CVSS3: 3.3
nvd
почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: smb3: fix temporary data corruption in collapse range collapse range doesn't discard the affected cached region so can risk temporarily corrupting the file data. This fixes xfstest generic/031 I also decided to merge a minor cleanup to this into the same patch (avoiding rereading inode size repeatedly unnecessarily) to make it clearer.

msrc
5 месяцев назад

smb3: fix temporary data corruption in collapse range

CVSS3: 3.3
debian
почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: s ...

CVSS3: 3.3
github
почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: smb3: fix temporary data corruption in collapse range collapse range doesn't discard the affected cached region so can risk temporarily corrupting the file data. This fixes xfstest generic/031 I also decided to merge a minor cleanup to this into the same patch (avoiding rereading inode size repeatedly unnecessarily) to make it clearer.

EPSS

Процентиль: 3%
0.00016
Низкий

6.1 Medium

CVSS3