PT-2022-32123 · Linux · Linux Kernel
Published
2022-06-28
·
Updated
2022-06-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux Kernel versions prior to v4.19.247
Description
The issue is related to a use-after-free error that occurs when volume creation fails in the
ubi create volume function. This problem was introduced in version v4.12 and is fixed in version v4.19.247. The actual impact and potential for attack have not been fully determined.Recommendations
For Linux Kernel versions prior to v4.19.247, update to version v4.19.247 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
ubi create volume function until a patch is applied. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel