kernel: information leak in copy_page_to_iter() in iov_iter.c
Published Aug 29, 2022
7.1
HIGHCVSS 3.1
EPSS 0.43%
Description
A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version Fixed in kernel v5.14 rc1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
- < 4.4.276
- ≥ 4.5 · < 4.9.276
- ≥ 4.10 · < 4.14.240
- ≥ 4.15 · < 4.19.198
- ≥ 4.20 · < 5.4.132
- ≥ 5.5.0 · < 5.10.50
- ≥ 5.11 · < 5.12.17
- ≥ 5.13 · < 5.13.2
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.9.1.el8
Fixed · RHSA-2022:1988
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-372.9.1.rt7.166.el8
Fixed · RHSA-2022:1975
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.9.1.el8 | Fixed | RHSA-2022:1988 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-372.9.1.rt7.166.el8 | Fixed | RHSA-2022:1975 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-0850 x_refsource_MISCThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2060606 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15893 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ce3aba43599f0b50adbebff133df8d08a3d5fffe x_refsource_MISCMailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0850
- https://syzkaller.appspot.com/bug?id=78e9ad0e6952a3ca16e8234724b2fa92d041b9b8 x_refsource_MISCExploitMailing ListThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0850
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0850 | x_refsource_MISCThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2060606 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15893 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ce3aba43599f0b50adbebff133df8d08a3d5fffe | x_refsource_MISCMailing ListPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0850 | ||
| https://syzkaller.appspot.com/bug?id=78e9ad0e6952a3ca16e8234724b2fa92d041b9b8 | x_refsource_MISCExploitMailing ListThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-0850 |
Change history (0)
No recorded changes yet.