PT-2022-7703 · Linux+1 · Linux Kernel+1
Bing-Jhong Billy Jheng
·
Published
2022-07-22
·
Updated
2023-02-03
·
CVE-2022-2327
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to the version containing commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859
Description
The issue is related to a double free vulnerability in the Linux kernel, specifically with the io uring feature. This vulnerability can be exploited to cause a denial of service. The
io uring use work flags to determine which identity needs to be grabbed from the calling process to ensure consistency when executing IORING OP. However, some operations are missing certain types, leading to incorrect reference counts and potentially resulting in a double free.Recommendations
To resolve the issue, upgrade the kernel past commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859. As a temporary workaround, consider restricting the use of the
io uring feature until a patch is available.Fix
Use After Free
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel