7
CVE-2022-28796
- EPSS 0.33%
- Veröffentlicht 08.04.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 06:57:57
- Erkennungen
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.17 < 5.17.1
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Fedoraproject ≫ Fedora Version 35
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vsphere
Netapp ≫ Solidfire, Enterprise Sds & Hci Storage Node Version -
Netapp ≫ Solidfire & Hci Management Node Version -
Netapp ≫ Hci Compute Node Firmware Version -
Netapp ≫ H300s Firmware Version -
Netapp ≫ H500s Firmware Version -
Netapp ≫ H700s Firmware Version -
Netapp ≫ H300e Firmware Version -
Netapp ≫ H500e Firmware Version -
Netapp ≫ H700e Firmware Version -
Netapp ≫ H410s Firmware Version -
Netapp ≫ H410c Firmware Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.25 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.1
https://security.netapp.com/advisory/ntap-20220506-0006/
https://github.com/torvalds/linux/commit/cc16eecae687912238ee6efbff71ad31e2bc414e