CVE-2022-2327

🟡 Monitoruj

Błąd w io_uring może prowadzić do podwójnego zwolnienia pamięci przez nieprawidłowe liczniki referencji.

CVSS
7.5
EPSS
0.3%
Exploit
none
Vendor
netapp
Opis źródłowy (NVD)

io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts which can then lead to a double free. We recommend upgrading the kernel past commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2022-07-22 10:15:08 UTC
Ostatnia modyfikacja (NVD)2026-10-02 13:56:14 UTC
Referencje