CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
68.0%
A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.
Vendor | Product | Version | CPE |
---|---|---|---|
linux | linux_kernel | * | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
linux | linux_kernel | 5.18 | cpe:2.3:o:linux:linux_kernel:5.18:-:*:*:*:*:*:* |
linux | linux_kernel | 5.18 | cpe:2.3:o:linux:linux_kernel:5.18:rc1:*:*:*:*:*:* |
linux | linux_kernel | 5.18 | cpe:2.3:o:linux:linux_kernel:5.18:rc2:*:*:*:*:*:* |
linux | linux_kernel | 5.18 | cpe:2.3:o:linux:linux_kernel:5.18:rc3:*:*:*:*:*:* |
redhat | enterprise_linux | 6.0 | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* |
netapp | active_iq_unified_manager | - | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* |
netapp | h300s_firmware | - | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* |
netapp | h300s | - | cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:* |
netapp | h500s_firmware | - | cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* |
[
{
"vendor": "n/a",
"product": "Kernel",
"versions": [
{
"version": "Fixed in kernel v5.18-rc4",
"status": "affected"
}
]
}
]
access.redhat.com/security/cve/CVE-2022-1199
bugzilla.redhat.com/show_bug.cgi?id=2070694
github.com/torvalds/linux/commit/4e0f718daf97d47cf7dec122da1be970f145c809
github.com/torvalds/linux/commit/71171ac8eb34ce7fe6b3267dce27c313ab3cb3ac
github.com/torvalds/linux/commit/7ec02f5ac8a5be5a3f20611731243dc5e1d9ba10
security.netapp.com/advisory/ntap-20221228-0006/
www.openwall.com/lists/oss-security/2022/04/02/5
More