4.7

CVE-2022-49603

ip: Fix data-races around sysctl_ip_fwd_update_priority.

In the Linux kernel, the following vulnerability has been resolved:

ip: Fix data-races around sysctl_ip_fwd_update_priority.

While reading sysctl_ip_fwd_update_priority, it can be changed
concurrently.  Thus, we need to add READ_ONCE() to its readers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.19 < 5.10.134
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.58
Linux ≫ Linux Kernel Version >= 5.16 < 5.18.15
Linux ≫ Linux Kernel Version 5.19 Update rc1
Linux ≫ Linux Kernel Version 5.19 Update rc2
Linux ≫ Linux Kernel Version 5.19 Update rc3
Linux ≫ Linux Kernel Version 5.19 Update rc4
Linux ≫ Linux Kernel Version 5.19 Update rc5
Linux ≫ Linux Kernel Version 5.19 Update rc6
Linux ≫ Linux Kernel Version 5.19 Update rc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.087
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.7 1 3.6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 4.7 1 3.6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

https://git.kernel.org/stable/c/11038fa781ab916535c53351537b22d6d405667d
Patch
https://git.kernel.org/stable/c/351f81f7d7185d18a9ff76f8f8c2fa8c4eea563b
Patch
https://git.kernel.org/stable/c/7bf9e18d9a5e99e3c83482973557e9f047b051e7
Patch
https://git.kernel.org/stable/c/bcc03369d3277ae075ed421f0c8bf4adb5e65b74
Patch