Linux Kernel Driver memory.c use after free
Published Oct 16, 2022
5.3
MEDIUMCVSS 3.1
EPSS 0.92%
Description
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unknown function of the file mm/memory.c of the component Driver Handler. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211020.
Affected products
- n/a
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
There was no shipped kernel version that was seen affected by this problem. These files are not built in our source code.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-3523 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2143906 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42890 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=16ce101db85db694a91380aa4c89b25530871d33 Mailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3523
- https://vuldb.com/?id.211020 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-3523
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3523 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2143906 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42890 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=16ce101db85db694a91380aa4c89b25530871d33 | Mailing ListPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3523 | ||
| https://vuldb.com/?id.211020 | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-3523 |
Change history (0)
No recorded changes yet.