CVE-2022-4379

high
Published 2023-02-28 · Modified 2023-02-28
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
8.0

Description

A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2022-4379 NameCVE-2022-4379 DescriptionA use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) ReferencesDLA-3404-1 Vulnerable…

CVE-2022-4379

NameCVE-2022-4379
DescriptionA use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3404-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)bullseye5.10.223-1fixed
bullseye (security)5.10.257-1fixed
bookworm6.1.170-3fixed
bookworm (security)6.1.172-1fixed
trixie6.12.86-1fixed
trixie (security)6.12.90-1fixed
forky7.0.9-1fixed
sid7.0.10-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcebuster(not affected)
linuxsourcebullseye5.10.178-1
linuxsource(unstable)6.1.4-1
linux-5.10sourcebuster5.10.178-3~deb10u1DLA-3404-1

Notes

[buster] - linux <not-affected> (Vulnerable code introduced later)
https://www.openwall.com/lists/oss-security/2022/12/14/3
https://lore.kernel.org/all/1670885411-10060-1-git-send-email-dai.ngo@oracle.com/

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[buster] - linux <not-affected> (Vulnerable code introduced later)https://www.openwall.com/lists/oss-security/2022/12/14/3https://lore.kernel.org/all/1670885411-10060-1-git-send-email-dai.ngo@oracle.com/

OS impact

OSVersionStatusFixed in
arch archfixed6.2-1
redhat rhel9fixed
suse slesaffected
debian debianbookwormfixed6.1.4-1
debian debianbullseyefixed5.10.178-1
debian debianforkyfixed6.1.4-1
debian debiansidfixed6.1.4-1
debian debiantrixiefixed6.1.4-1
rockylinux rocky9fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.