Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-49689

Опубликовано: 26 фев. 2025
Источник: redhat
CVSS3: 5.5

Описание

[REJECTED CVE] A vulnerability was identified in the Linux kernel’s xen-blkfront driver, where failing to fully initialize a virtual block device (VBD) before detaching it could lead to a NULL pointer dereference due to gendisk being NULL. An attacker with control over a guest VM could exploit this by attaching an invalid or non-existent backend device and then detaching it, triggering a kernel crash or denial of service in the host through a NULL dereference during cleanup in blkfront_closing().

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelAffected
Red Hat Enterprise Linux 9kernel-rtAffected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2348021kernel: xen-blkfront: Handle NULL gendisk

5.5 Medium

CVSS3

Связанные уязвимости

nvd
12 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

5.5 Medium

CVSS3

Уязвимость CVE-2022-49689