Oval Definition:oval:org.opensuse.security:def:20223910
Revision Date:2023-02-11Version:1
Title:CVE-2022-3910
Description:

Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_uring leads to Use-After-Free and Local Privilege Escalation. When io_msg_ring was invoked with a fixed file, it called io_fput_file() which improperly decreased its reference count (leading to Use-After-Free and Local Privilege Escalation). Fixed files are permanently registered to the ring, and should not be put separately. We recommend upgrading past commit https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679 https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2022-3910
SUSE CVE-2022-3910
Platform(s):SUSE Linux Enterprise Micro 5.3
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Micro 5.3 is installed
  • AND Package Information
  • kernel-default is not affected
  • OR kernel-rt is not affected
  • BACK