Lucene search

K
redhatcveRedhat.comRH:CVE-2022-41850
HistorySep 30, 2022 - 8:19 p.m.

CVE-2022-41850

2022-09-3020:19:08
redhat.com
access.redhat.com
23
hid
linux kernel
denial of service
usb
roccat
mitigation

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%

A race issue was found in roccat_report_event in drivers/hid/hid-roccat.c in the Human Interface Devices (HID) sub-component in the Linux kernel. This flaw allows a local attacker with a standard user privilege to cause a denial of service.

Mitigation

This flaw can be mitigated by preventing the affected USB Roccat kernel module from loading during the boot time. Ensure the module is added into the blacklist file.

Refer:    
How do I blacklist a kernel module to prevent it from loading automatically?   
https://access.redhat.com/solutions/41278  

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%