kernel: possible use after free in lock_sock_nested of sock.c for the SCTP protocol
Published Jun 15, 2022
6.4
MEDIUMCVSS 3.1
EPSS 0.11%
Description
In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174846563References: Upstream kernel
Affected products
- Vendor n/a Product Android Defaultn/a
- Version Android kernelStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Android | n/a |
|
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this issue, prevent the sctp module from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-20154 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2150863 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-25414 Advisory
- https://github.com/torvalds/linux/commit/5ec7d18d1813a5bead0b495045606c93873aecbb
- https://nvd.nist.gov/vuln/detail/CVE-2022-20154
- https://source.android.com/security/bulletin/pixel/2022-06-01 x_refsource_MISCVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-20154
Change history (0)
No recorded changes yet.