kernel: watch queue race condition can lead to privilege escalation
Published Aug 25, 2022
7.0
HIGHCVSS 3.1
EPSS 0.38%
Description
A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an object. This flaw allows a local user to crash the system or escalate their privileges on the system.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version Fixed in kernel 5.19StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
- ≥ 5.8 · < 5.10.120
- ≥ 5.11 · < 5.15.45
- ≥ 5.16 · < 5.17.13
- ≥ 5.18 · < 5.18.2
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.12.1.el9_1
Fixed · RHSA-2023:0334
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.12.1.el9_1
Fixed · RHSA-2023:0334
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-162.12.1.rt21.175.el9_1
Fixed · RHSA-2023:0300
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2023:0348
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.36.1.el9_0
Fixed · RHSA-2022:8973
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.36.1.rt21.108.el9_0
Fixed · RHSA-2022:8974
Red Hat Enterprise Linux 9.0 Extended Update Support
kpatch-patch
Fixed · RHSA-2022:9082
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.12.1.el9_1 | Fixed | RHSA-2023:0334 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.12.1.el9_1 | Fixed | RHSA-2023:0334 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-162.12.1.rt21.175.el9_1 | Fixed | RHSA-2023:0300 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2023:0348 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.36.1.el9_0 | Fixed | RHSA-2022:8973 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.36.1.rt21.108.el9_0 | Fixed | RHSA-2022:8974 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kpatch-patch | Fixed | RHSA-2022:9082 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 6, 7 and 8 are not affected by this issue as they did not include support for general notification queue.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-2959 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2103681 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-35180 Advisory
- https://github.com/torvalds/linux/commit/189b0ddc245139af81198d1a3637cac74f96e13a PatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2959
- https://security.netapp.com/advisory/ntap-20230214-0005/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-2959
- https://www.zerodayinitiative.com/advisories/ZDI-22-1165/ Third Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2959 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2103681 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-35180 | Advisory | |
| https://github.com/torvalds/linux/commit/189b0ddc245139af81198d1a3637cac74f96e13a | PatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2959 | ||
| https://security.netapp.com/advisory/ntap-20230214-0005/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-2959 | ||
| https://www.zerodayinitiative.com/advisories/ZDI-22-1165/ | Third Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.