Lucene search

K
cve[email protected]CVE-2022-3176
HistorySep 16, 2022 - 2:15 p.m.

CVE-2022-3176

2022-09-1614:15:09
CWE-416
web.nvd.nist.gov
112
10
cve-2022-3176
use-after-free
io_uring
linux kernel
signalfd_poll()
binder_poll()
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.3%

There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is freed. Unfortunately, the io_uring poll doesn’t handle POLLFREE. This allows a use-after-free to occur if a signalfd or binder fd is polled with io_uring poll, and the waitqueue gets freed. We recommend upgrading past commit fc78b2fc21f10c4c9c4d5d659a685710ffa63659

Affected configurations

NVD
Node
linuxlinux_kernelRange5.15.4.212
OR
linuxlinux_kernelRange5.55.10.141
OR
linuxlinux_kernelRange5.115.15.65
OR
linuxlinux_kernelRange5.165.17
Node
debiandebian_linuxMatch10.0
OR
debiandebian_linuxMatch11.0

CNA Affected

[
  {
    "vendor": "Linux",
    "product": "Kernel",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "fc78b2fc21f10c4c9c4d5d659a685710ffa63659",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.3%