Use-after-free in io_uring in Linux Kernel
Published Sep 16, 2022
7.8
HIGHCVSS 3.1
EPSS 0.30%
Description
There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is freed. Unfortunately, the io_uring poll doesn't handle POLLFREE. This allows a use-after-free to occur if a signalfd or binder fd is polled with io_uring poll, and the waitqueue gets freed. We recommend upgrading past commit fc78b2fc21f10c4c9c4d5d659a685710ffa63659
Affected products
-
- Version unspecifiedStatusaffectedConstraints
- Version
Configuration 1
- ≥ 5.1 · < 5.4.212
- ≥ 5.5 · < 5.10.141
- ≥ 5.11 · < 5.15.65
- ≥ 5.16 · < 5.17
Configuration 2
- 10.0
- 11.0
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-3176 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2127890 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42594 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit?h=linux-5.4.y&id=fc78b2fc21f10c4c9c4d5d659a685710ffa63659 Mailing ListPatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fc78b2fc21f10c4c9c4d5d659a685710ffa63659
- https://kernel.dance/#fc78b2fc21f10c4c9c4d5d659a685710ffa63659 PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3176
- https://security.netapp.com/advisory/ntap-20230216-0003/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-3176
- https://www.debian.org/security/2022/dsa-5257 vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3176 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2127890 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42594 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit?h=linux-5.4.y&id=fc78b2fc21f10c4c9c4d5d659a685710ffa63659 | Mailing ListPatchVendor Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fc78b2fc21f10c4c9c4d5d659a685710ffa63659 | ||
| https://kernel.dance/#fc78b2fc21f10c4c9c4d5d659a685710ffa63659 | PatchVendor Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3176 | ||
| https://security.netapp.com/advisory/ntap-20230216-0003/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-3176 | ||
| https://www.debian.org/security/2022/dsa-5257 | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.