PT-2022-7480 · Linux+2 · Linux Kernel+2
Yu Kuai
·
Published
2022-02-28
·
Updated
2024-09-27
·
CVE-2022-48913
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.17.0-rc4-next-20220217+
Description
The issue is related to a use-after-free vulnerability in the blktrace component of the Linux kernel. This vulnerability can be triggered when tracing the whole disk, and 'dropped' and 'msg' files are created under 'q->debugfs dir' with 'bt->dir' being NULL, thus blk trace free() won't remove those files. As a result, accessing stale 'dropped' and 'msg' can lead to a use-after-free (UAF) condition. The vulnerability may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations
To resolve this issue, update the Linux kernel to a version that includes the fix for the blktrace use-after-free vulnerability, which is at least version 5.17.0-rc4-next-20220217+.
As a temporary workaround, consider disabling the blktrace functionality until a patch is available.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Red Os
Suse