Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-40476
HistorySep 14, 2022 - 12:00 a.m.

CVE-2022-40476

2022-09-1400:00:00
ubuntu.com
ubuntu.com
19
cve-2022-40476
fs/io_uring.c
local user
system crash
denial of service
unix

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

5.1%

A null pointer dereference issue was discovered in fs/io_uring.c in the
Linux kernel before 5.15.62. A local user could use this flaw to crash the
system or potentially cause a denial of service.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

5.1%