MEDIUM
kernel: refcount leak in llc_ui_bind and llc_ui_autobind
Published Apr 2, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.58%
Description
In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c.
Affected products
No data.
Configuration 1
- < 5.17.1
Configuration 2
OR
- 9.0
- 10.0
- 11.0
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (12)
- http://www.openwall.com/lists/oss-security/2022/04/06/1 mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-28356 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2074441 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.1 x_refsource_MISCPatchRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-32806 Advisory
- https://github.com/torvalds/linux/commit/764f4eb6846f5475f1244767d24d25dd86528a4a x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-28356
- https://security.netapp.com/advisory/ntap-20220506-0006/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-28356
- https://www.debian.org/security/2022/dsa-5127 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2022/dsa-5173 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 2, 2022
Updated May 5, 2025
Reserved Apr 2, 2022
Link CVE-2022-28356
CISA Vulnrichment
Updated Apr 23, 2025
ENISA EUVD
EUVD-2022-32806 Assigner mitre
Published Apr 2, 2022
Updated May 5, 2025
Exploited since n/a
Link EUVD-2022-32806