Lucene search

K
vulnrichmentLinuxVULNRICHMENT:CVE-2022-48757
HistoryJun 20, 2024 - 11:13 a.m.

CVE-2022-48757 net: fix information leakage in /proc/net/ptype

2024-06-2011:13:36
Linux
github.com
1
linux kernel
information leakage
net namespace
packet socket

AI Score

6.4

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

In the Linux kernel, the following vulnerability has been resolved:

net: fix information leakage in /proc/net/ptype

In one net namespace, after creating a packet socket without binding
it to a device, users in other net namespaces can observe the new
packet_type added by this packet socket by reading /proc/net/ptype
file. This is minor information leakage as packet socket is
namespace aware.

Add a net pointer in packet_type to keep the net namespace of
of corresponding packet socket. In ptype_seq_show, this net pointer
must be checked when it is not NULL.

AI Score

6.4

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial