PT-2022-2238 · Linux+1 · Linux Kernel+1

Published

2022-02-26

·

Updated

2023-08-29

·

CVE-2022-28796

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17.1
Description The issue is related to the jbd2 journal wait updates function in the Linux kernel, specifically in the fs/jbd2/transaction.c file. It involves a use-after-free condition caused by a transaction t race condition, which can be exploited by a remote attacker to execute arbitrary code.
Recommendations For Linux kernel versions prior to 5.17.1, update to version 5.17.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the jbd2 journal wait updates function until a patch is available.

Fix

Use After Free

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1647
ALT-PU-2022-1730
ALT-PU-2022-1768
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-9331
BDU:2022-02328
CVE-2022-28796

Affected Products

Alt Linux
Linux Kernel