PT-2022-1572 · Linux+9 · Linux Kernel+9

Lyu Tao

·

Published

2022-01-06

·

Updated

2024-12-10

·

CVE-2022-24448

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.16.5
Description An issue was discovered in the Linux kernel where the nfs atomic open() function performs a regular lookup when an application sets the O DIRECTORY flag and tries to open a regular file. Instead of returning an ENOTDIR error, the server returns uninitialized data in the file descriptor. This issue is related to the lack of resource initialization in the nfs atomic open() function implementation, which could allow an attacker to impact data confidentiality.
Recommendations For Linux kernel versions prior to 5.16.5, update to version 5.16.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the nfs atomic open() function to minimize the risk of exploitation. Avoid using the O DIRECTORY flag when trying to open regular files until the issue is resolved.

Fix

Use of Uninitialized Resource

Buffer Overflow

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:7444
ALSA-2022:7683
ALSA-2022:7933
ALSA-2022:8267
ALT-PU-2022-1197
ALT-PU-2022-1239
ALT-PU-2022-1647
ALT-PU-2022-2008
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-8483
BDU:2022-00790
CESA-2022_7444
CESA-2022_7683
CVE-2022-24448
DLA-2940-1
DLA-2941-1
DSA-5092-1
DSA-5096-1
MGASA-2022-0062
MGASA-2022-0063
OESA-2022-1539
OPENSUSE-SU-2022:0768-1
OPENSUSE-SU-2022:1037-1
OPENSUSE-SU-2022:1039-1
OPENSUSE-SU-2022_0768-1
OPENSUSE-SU-2022_1037-1
OPENSUSE-SU-2022_1039-1
OPENSUSE-SU-2022_2079-1
RHSA-2022:7444
RHSA-2022:7683
RHSA-2022:7933
RHSA-2022:8267
RHSA-2022_7444
RHSA-2022_7683
RHSA-2022_7933
RHSA-2022_8267
RHSA-2024:0724
RLSA-2022:7444
RLSA-2022:7683
SUSE-SU-2022:0555-1
SUSE-SU-2022:0756-1
SUSE-SU-2022:0757-1
SUSE-SU-2022:0759-1
SUSE-SU-2022:0762-1
SUSE-SU-2022:0765-1
SUSE-SU-2022:0766-1
SUSE-SU-2022:0767-1
SUSE-SU-2022:0768-1
SUSE-SU-2022:1037-1
SUSE-SU-2022:1038-1
SUSE-SU-2022:1039-1
SUSE-SU-2022:1257-1
SUSE-SU-2022:2079-1
SUSE-SU-2022:2080-1
USN-5302-1
USN-5383-1
USN-5384-1
USN-5385-1
USN-7148-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu