PT-2022-7434 · Linux+4 · Linux Kernel+4
Syzbot
·
Published
2022-09-08
·
Updated
2024-08-21
·
CVE-2022-48659
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the
kmalloc() function in the Linux kernel, which can fail due to out-of-memory conditions. If it fails, the function should return an error code (errno) instead of triggering a panic via BUG ON(). The vulnerability can cause a kernel bug, leading to an internal error and a potential denial-of-service condition. The create unique id() function is affected, and the issue is related to the mm/slub component of the kernel. The call trace includes functions such as sysfs slab add(), kmem cache create(), and f2fs kmem cache create().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse
Ubuntu