Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-49143

Опубликовано: 26 фев. 2025
Источник: redhat
CVSS3: 6.7

Описание

A vulnerability was found in the Linux kernel's Network Block Device (NBD) subsystem. The issue involved a potential integer overflow in the nbd_dev_add() function, where large values of the index parameter could lead to incorrect calculations of the first_minor value. This miscalculation may result in the creation of duplicate device entries in the sysfs filesystem, causing system instability or other unintended behaviors.

Отчет

This CVE has since been rejected by its CVE Numbering Authority (CNA), kernel.org. According to the National Vulnerability Database (NVD), the rejection indicates that the CVE ID has been withdrawn and should not be used as a reference for this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelOut of support scope
Red Hat Enterprise Linux 8kernel-rtOut of support scope
Red Hat Enterprise Linux 9kernelAffected
Red Hat Enterprise Linux 9kernel-rtAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2347893kernel: nbd: fix possible overflow on 'first_minor' in nbd_dev_add()

6.7 Medium

CVSS3

Связанные уязвимости

nvd
12 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

6.7 Medium

CVSS3