hw: Intel: Incorrect default peinrmissions in QAT driver enable escalation of privilege
Published Feb 16, 2023
7.8
HIGHCVSS 3.1
EPSS 0.23%
Description
Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected products
- Vendor n/a Product Intel(R) QAT drivers for Linux Defaultunaffected
- Version before version 4.17StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Intel(R) QAT drivers for Linux | unaffected |
|
- < 1.6
- < 4.17
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Please contact the hardware vendor for more update.
References (7)
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00751.html PatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2022-36397 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2209310 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-39110 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-36397
- https://www.cve.org/CVERecord?id=CVE-2022-36397
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00751.html
Change history (0)
No recorded changes yet.