-

CVE-2022-50490

In the Linux kernel, the following vulnerability has been resolved:

bpf: Propagate error from htab_lock_bucket() to userspace

In __htab_map_lookup_and_delete_batch() if htab_lock_bucket() returns
-EBUSY, it will go to next bucket. Going to next bucket may not only
skip the elements in current bucket silently, but also incur
out-of-bound memory access or expose kernel memory to userspace if
current bucket_cnt is greater than bucket_size or zero.

Fixing it by stopping batch operation and returning -EBUSY when
htab_lock_bucket() fails, and the application can retry or skip the busy
batch as needed.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 0e13425104903970a5ede853082d3bbb4edec6f3
Version 20b6cc34ea74b6a84599c1f8a70f3315b56a1883
Status affected
Version < 6bfee6eb3d6b96ae730a542909dd22b5f9f50d58
Version 20b6cc34ea74b6a84599c1f8a70f3315b56a1883
Status affected
Version < 4f1f39a8f1ce1b24fee6852d7dcd704ce7c4334d
Version 20b6cc34ea74b6a84599c1f8a70f3315b56a1883
Status affected
Version < 66a7a92e4d0d091e79148a4c6ec15d1da65f4280
Version 20b6cc34ea74b6a84599c1f8a70f3315b56a1883
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.11
Status affected
Version < 5.11
Version 0
Status unaffected
Version <= 5.15.*
Version 5.15.75
Status unaffected
Version <= 5.19.*
Version 5.19.17
Status unaffected
Version <= 6.0.*
Version 6.0.3
Status unaffected
Version <= *
Version 6.1
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.031
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string