PT-2022-5915 · Linux+3 · Linux Kernel+3

Jiasheng Jiang

·

Published

2022-01-19

·

Updated

2023-08-14

·

CVE-2022-3104

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.16-rc6
Description The issue is related to the lkdtm ARRAY BOUNDS function in the drivers/misc/lkdtm/bugs.c module of the Linux kernel. It lacks a check of the return value of kmalloc() and will cause a null pointer dereference. This can lead to a denial of service or potentially allow an attacker to elevate their privileges.
Recommendations For Linux kernel versions prior to 5.16-rc6, consider disabling the lkdtm ARRAY BOUNDS function in the drivers/misc/lkdtm/bugs.c module as a temporary workaround until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using the kmalloc() function in the affected module until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1093
ALT-PU-2022-1175
ALT-PU-2022-1647
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-11605
BDU:2022-07332
CVE-2022-3104
OESA-2023-1035
OPENSUSE-SU-2023_0146-1
OPENSUSE-SU-2023_0147-1
OPENSUSE-SU-2023_0149-1
SUSE-SU-2023:0146-1
SUSE-SU-2023:0147-1
SUSE-SU-2023:0149-1
SUSE-SU-2023_0146-1
SUSE-SU-2023_0147-1
SUSE-SU-2023_0149-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Suse