An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.
References
| Link | Resource |
|---|---|
| https://gitee.com/anolis/cloud-kernel/commit/bed537da691b | Permissions Required |
| https://bugzilla.openanolis.cn/show_bug.cgi?id=61 | Issue Tracking Patch Third Party Advisory |
| https://lore.kernel.org/all/20200602080425.93712-1-kerneljasonxing@gmail.com/ | Exploit Patch Vendor Advisory |
| https://github.com/torvalds/linux/commit/0a70f118475e037732557796accd0878a00fc25a | Patch Third Party Advisory |
| https://anas.openanolis.cn/cves/detail/CVE-2022-1678 | |
| https://anas.openanolis.cn/errata/detail/ANSA-2022:0143 | |
| https://security.netapp.com/advisory/ntap-20220715-0001/ |
Configurations
Information
Published : 2022-05-25 15:15
Updated : 2022-07-15 16:15
NVD link : CVE-2022-1678
Mitre link : CVE-2022-1678
JSON object : View
Products Affected
linux
- linux_kernel
CWE
