kernel: use-after-free in efi_capsule_write in capsule-loader.c
Published Sep 9, 2022
4.7
MEDIUMCVSS 3.1
EPSS 0.21%
Description
An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.
Affected products
No data.
Configuration 1
- ≤ 5.19.8
Configuration 2
- 10.0
Configuration 3
- 10.0
- 11.0
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not affected by this flaw as the EFI capsule loader is not enabled in any current shipping kernels.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-40307 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2127424 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43604 Advisory
- https://github.com/torvalds/linux/commit/9cb636b5f6a8cc6d1b50809ec8f8d33ae0c84c95 PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-40307
- https://www.cve.org/CVERecord?id=CVE-2022-40307
- https://www.debian.org/security/2022/dsa-5257 vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-40307 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2127424 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43604 | Advisory | |
| https://github.com/torvalds/linux/commit/9cb636b5f6a8cc6d1b50809ec8f8d33ae0c84c95 | PatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html | mailing-listMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-40307 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-40307 | ||
| https://www.debian.org/security/2022/dsa-5257 | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data