7.8

CVE-2022-48771

drm/vmwgfx: Fix stale file descriptors on failed usercopy

In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx: Fix stale file descriptors on failed usercopy

A failing usercopy of the fence_rep object will lead to a stale entry in
the file descriptor table as put_unused_fd() won't release it. This
enables userland to refer to a dangling 'file' object through that still
valid file descriptor, leading to all kinds of use-after-free
exploitation scenarios.

Fix this by deferring the call to fd_install() until after the usercopy
has succeeded.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.14 < 4.14.264
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.227
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.175
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.95
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.18
Linux ≫ Linux Kernel Version >= 5.16 < 5.16.4
Linux ≫ Linux Kernel Version 5.17 Update rc1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.114
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

https://git.kernel.org/stable/c/0008a0c78fc33a84e2212a7c04e6b21a36ca6f4d
Patch
https://git.kernel.org/stable/c/1d833b27fb708d6fdf5de9f6b3a8be4bd4321565
Patch
https://git.kernel.org/stable/c/6066977961fc6f437bc064f628cf9b0e4571c56c
Patch
https://git.kernel.org/stable/c/84b1259fe36ae0915f3d6ddcea6377779de48b82
Patch
https://git.kernel.org/stable/c/a0f90c8815706981c483a652a6aefca51a5e191c
Patch
https://git.kernel.org/stable/c/ae2b20f27732fe92055d9e7b350abc5cdf3e2414
Patch
https://git.kernel.org/stable/c/e8d092a62449dcfc73517ca43963d2b8f44d0516
Patch