7.8

CVE-2022-4139

An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or escalate their privileges on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.4 < 5.4.226
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.157
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.81
Linux ≫ Linux Kernel Version >= 5.16 < 6.0.11
Linux ≫ Linux Kernel Version 6.1 Update -
Linux ≫ Linux Kernel Version 6.1 Update rc1
Linux ≫ Linux Kernel Version 6.1 Update rc2
Linux ≫ Linux Kernel Version 6.1 Update rc3
Linux ≫ Linux Kernel Version 6.1 Update rc4
Linux ≫ Linux Kernel Version 6.1 Update rc5
Linux ≫ Linux Kernel Version 6.1 Update rc6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.163
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-281 Improper Preservation of Permissions

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

https://bugzilla.redhat.com/show_bug.cgi?id=2147572
Patch
Third Party Advisory
Issue Tracking
https://security.netapp.com/advisory/ntap-20230309-0004/
Third Party Advisory
https://www.openwall.com/lists/oss-security/2022/11/30/1
Third Party Advisory
Mailing List