CVE-2022-48816
🟡 Monitoruj
Wyścig warunków w jądrze Linuxa może prowadzić do błędu oops podczas odczytu sysfs.
CVSS
7.8
EPSS
0.3%
Exploit
none
Vendor
linux
Opis źródłowy (NVD)
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: lock against ->sock changing during sysfs read ->sock can be set to NULL asynchronously unless ->recv_mutex is held. So it is important to hold that mutex. Otherwise a sysfs read can trigger an oops. Commit 17f09d3f619a ("SUNRPC: Check if the xprt is connected before handling sysfs reads") appears to attempt to fix this problem, but it only narrows the race window.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2024-07-16 12:15:05 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:25 UTC |
Referencje
- https://git.kernel.org/stable/c/9482ab4540f5bcc869b44c067ae99b5fca16bd07 (416baaa9-dc9f-4396-8d5f-8c081fb06d67) [Patch]
- https://git.kernel.org/stable/c/b49ea673e119f59c71645e2f65b3ccad857c90ee (416baaa9-dc9f-4396-8d5f-8c081fb06d67) [Patch]
- https://git.kernel.org/stable/c/cd366b9091a3e6ed8229e4b908e895d20b527dc0 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/fdc42287ae3f8a35cc2098307f52d7864b4bc8ed (416baaa9-dc9f-4396-8d5f-8c081fb06d67)