kernel: xfrm_expand_policies() in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice
Published Jul 27, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.32%
Description
An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.
Affected products
No data.
Configuration 1
- ≤ 5.18.14
Configuration 2
- 10.0
- 11.0
Configuration 3
- n/a
Configuration 4
- n/a
- ≥ 11.0 · ≤ 11.50.2
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 14
- n/a
Configuration 15
- n/a
Configuration 16
- n/a
Configuration 17
- n/a
Configuration 18
- n/a
Configuration 19
- n/a
Configuration 20
- n/a
Configuration 21
- n/a
Configuration 22
- n/a
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-477.10.1.el8_8
Fixed · RHSA-2023:2951
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-477.10.1.rt7.274.el8_8
Fixed · RHSA-2023:2736
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.75.1.el8_6
Fixed · RHSA-2023:5627
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-284.11.1.rt14.296.el9_2
Fixed · RHSA-2023:2148
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.85.1.el9_0
Fixed · RHSA-2024:0432
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.85.1.rt21.156.el9_0
Fixed · RHSA-2024:0431
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.75.1.el8_6
Fixed · RHSA-2023:5627
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-477.10.1.el8_8 | Fixed | RHSA-2023:2951 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-477.10.1.rt7.274.el8_8 | Fixed | RHSA-2023:2736 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.75.1.el8_6 | Fixed | RHSA-2023:5627 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-284.11.1.rt14.296.el9_2 | Fixed | RHSA-2023:2148 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.85.1.el9_0 | Fixed | RHSA-2024:0432 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.85.1.rt21.156.el9_0 | Fixed | RHSA-2024:0431 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.75.1.el8_6 | Fixed | RHSA-2023:5627 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-36879 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2119855 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-39579 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=f85daf0e725358be78dfd208dea5fd665d8cb901 x_refsource_MISCMailing ListPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/f85daf0e725358be78dfd208dea5fd665d8cb901 x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00011.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-36879
- https://security.netapp.com/advisory/ntap-20220901-0007/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-36879
- https://www.debian.org/security/2022/dsa-5207 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data