kernel: user-after-free during IORING_OP_SPLICE operation
Published Jan 11, 2023
7.8
HIGHCVSS 3.1
EPSS 0.43%
Description
There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter is not increased. This assumption is not always true as calling io_splice on specific files will call the get_uts function which will use current->nsproxy leading to invalidly decreasing its reference counter later causing the use-after-free vulnerability. We recommend upgrading to version 5.10.160 or above
Affected products
-
- Version 5.7-rc1StatusaffectedConstraints<=5.10.159
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux Kernel | unaffected |
|
Configuration 1
- n/a
Configuration 2
- n/a
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- ≥ 5.4 · < 5.10.160
- ≥ 5.11 · < 5.12
-
- Version 5.7-rc1StatusaffectedConstraints<=5.10.159
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux Kernel | n/a |
|
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not affected by this flaw as the io_uring (CONFIG_IO_URING) is not enabled in any current shipping kernels.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Aug 1, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2023-2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (8 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.43% (0.00432) | 35.31th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.41% (0.00407) | 32.16th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.01% (0.00013) | 1.02th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00048) | 19.71th | v3 (v2023.03.01) |
| Jun 13, 2024 | 0.04% (0.00043) | 8.98th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00043) | 6.97th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Jan 12, 2023 | 0.89% (0.00885) | 27.30th | v2 (v2022.01.01) |
References (7)
- https://access.redhat.com/security/cve/CVE-2022-4696 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2164424 Issue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=linux-5.10.y&id=75454b4bbfc7e6a4dd8338556f36ea9107ddf61a Mailing ListPatchVendor Advisory
- https://kernel.dance/#75454b4bbfc7e6a4dd8338556f36ea9107ddf61a ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-4696
- https://security.netapp.com/advisory/ntap-20230223-0003/ Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-4696
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-4696 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2164424 | Issue Tracking | |
| https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=linux-5.10.y&id=75454b4bbfc7e6a4dd8338556f36ea9107ddf61a | Mailing ListPatchVendor Advisory | |
| https://kernel.dance/#75454b4bbfc7e6a4dd8338556f36ea9107ddf61a | ExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-4696 | ||
| https://security.netapp.com/advisory/ntap-20230223-0003/ | Vendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-4696 |
Change history (0)
No recorded changes yet.