-

CVE-2022-49852

In the Linux kernel, the following vulnerability has been resolved:

riscv: process: fix kernel info leakage

thread_struct's s[12] may contain random kernel memory content, which
may be finally leaked to userspace. This is a security hole. Fix it
by clearing the s[12] array in thread_struct when fork.

As for kthread case, it's better to clear the s[12] array as well.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < c4601d30f7d989b4f354df899ab85b5f7a750d30
Version 7db91e57a0acde126a162ababfb1e0ab190130cb
Status affected
Version < c5c0b3167537793a7cf936fb240366eefd2fc7fb
Version 7db91e57a0acde126a162ababfb1e0ab190130cb
Status affected
Version < e56d18a976dda653194218df6d40d8122c775712
Version 7db91e57a0acde126a162ababfb1e0ab190130cb
Status affected
Version < cc36c7fa5d9384602529ba3eea8c5daee7be4dbc
Version 7db91e57a0acde126a162ababfb1e0ab190130cb
Status affected
Version < 358a68f98304b40b201ba5afe94c20355aa3dc68
Version 7db91e57a0acde126a162ababfb1e0ab190130cb
Status affected
Version < 6510c78490c490a6636e48b61eeaa6fb65981f4b
Version 7db91e57a0acde126a162ababfb1e0ab190130cb
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.15
Status affected
Version < 4.15
Version 0
Status unaffected
Version <= 4.19.*
Version 4.19.267
Status unaffected
Version <= 5.4.*
Version 5.4.225
Status unaffected
Version <= 5.10.*
Version 5.10.155
Status unaffected
Version <= 5.15.*
Version 5.15.79
Status unaffected
Version <= 6.0.*
Version 6.0.9
Status unaffected
Version <= *
Version 6.1
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.131
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.