Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-45887
HistoryNov 25, 2022 - 12:00 a.m.

CVE-2022-45887

2022-11-2500:00:00
ubuntu.com
ubuntu.com
15
cve-2022-45887
linux kernel
memory leak

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%

An issue was discovered in the Linux kernel through 6.0.9.
drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the
lack of a dvb_frontend_detach call.

Bugs

Notes

Author Note
rodrigo-zaiden exploiting this vulnerability requires disconnecting a DVB device.

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%