4.7

CVE-2022-49637

ipv4: Fix a data-race around sysctl_fib_sync_mem.

In the Linux kernel, the following vulnerability has been resolved:

ipv4: Fix a data-race around sysctl_fib_sync_mem.

While reading sysctl_fib_sync_mem, it can be changed concurrently.
So, we need to add READ_ONCE() to avoid a data-race.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.2 < 5.4.207
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.132
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.56
Linux ≫ Linux Kernel Version >= 5.16 < 5.18.13
Linux ≫ Linux Kernel Version 5.19 Update rc1
Linux ≫ Linux Kernel Version 5.19 Update rc2
Linux ≫ Linux Kernel Version 5.19 Update rc3
Linux ≫ Linux Kernel Version 5.19 Update rc4
Linux ≫ Linux Kernel Version 5.19 Update rc5
Linux ≫ Linux Kernel Version 5.19 Update rc6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.074
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.7 1 3.6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 4.7 1 3.6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

https://git.kernel.org/stable/c/190cd4ff128373271e065afb20f1d2247b3f10c3
Patch
https://git.kernel.org/stable/c/418b191d5f223a8cb6cab09eae1f72c04ba6adf2
Patch
https://git.kernel.org/stable/c/73318c4b7dbd0e781aaababff17376b2894745c0
Patch
https://git.kernel.org/stable/c/7c1acd98fb221dc0d847451b9ab86319f8b9916c
Patch
https://git.kernel.org/stable/c/9be8aac91960ea32fd0e874758c9afee665c57d2
Patch